Privacy Policy
Corrigenda AB
1. Who we are and what this policy covers
Corrigenda AB (“Corrigenda”, “we”, “us”) provides review software for primary-care centres that draft their notes with an AI scribe. A browser extension installed by the care provider’s IT records, for each consultation, the clinician’s consent confirmation, the draft the scribe showed, the text approved into the journal and the scribe’s version. A classifier flags passages likely to hold a transcription error and puts them, with a random sample, in a review queue worked by a clinician the care provider names from its own staff. A correction log records every request to an author and how it was closed. Nobody who works for Corrigenda reads a note, we never hold audio, we never write to the journal, and nothing the model scores changes a note.
Registered at Östra Hamngatan 16, 411 09 Göteborg, Sweden.
We handle personal data in two different situations, and different rules apply to each:
| Whose data | Our role | What applies | |
|---|---|---|---|
| Part A | People who visit this website, ask about the service or write to us | Controller: we decide why and how the data is used | This policy |
| Part B | For each scribe-drafted consultation at a connected centre: the consent mark, the draft, the approved text and the changes between them, the scribe version and the times, and the author as the journal system shows them. Also the reviewer’s verdicts, correction requests and closures, the passage-and-verdict pairs that come from them, the twelve-month export of past notes handed over at onboarding, and the care provider’s account, contract and invoice records. | Set out in B.1, because it depends on the data | This policy and the data processing agreement we sign with each customer |
If the data processing agreement (“DPA”) and this policy ever disagree about Part B, the DPA wins.
2. Part A: this website and our contact with you
This part covers the personal data we collect for our own purposes: running this website, answering requests, and staying in touch with people who are or might become customers.
A.1 What we collect
What you give us. When you send the form on this site, we collect what you type into it, such as your name, email address, phone number or company, and the fact that you agreed to be contacted. If you email or talk to us, we keep that correspondence and any contact details in it.
What is collected automatically. Our web server records the IP address a request came from, the browser used, the pages requested, the page you came from and the time. These logs exist to keep the site running and secure.
We don’t ask for sensitive data (the “special categories” in Article 9 GDPR) through this website, so please don’t send any through the form.
A.2 Why we use it, and what allows us to
| Why | What | Legal basis (GDPR Art. 6) |
|---|---|---|
| Answering your request and working out whether the service fits | What you sent in the form, our correspondence | Art. 6(1)(b): steps you asked for before a contract |
| Looking after customers, billing and support | Contact details, correspondence | Art. 6(1)(b): carrying out a contract |
| Keeping the site running, secure and free of abuse | Server logs | Art. 6(1)(f): our legitimate interest in running a secure service |
| Contacting you about the service | Email address, company | Art. 6(1)(f): our legitimate interest in business-to-business marketing. You can object at any time |
| Meeting tax, accounting and legal duties | Billing and contract records | Art. 6(1)(c): a legal obligation |
Where we rely on legitimate interest, we have weighed that interest against your rights, and you can ask to see the assessment.
A.3 How long we keep it
- Requests from people who don’t become customers: 12 months from our last contact, then deleted.
- Customer contact and contract records: for the length of the agreement plus 6 years, to cover legal claims and accounting rules.
- Server logs: 30 days.
- A record that you objected or opted out: kept indefinitely, so we can keep respecting it.
A.4 Your rights
If you are in the EEA or the UK, you can ask to see your data, correct it, have it deleted, limit or object to how we use it, get a copy you can take elsewhere, and withdraw consent where we rely on it. Write to [email protected] and we will answer within one month.
You can also complain to a data protection authority. If you are in the EEA, that can be the authority where you live or work.
3. Part B: data inside the service
Two kinds of data pass through this service, and we treat them differently. The first is patient data: the text of a clinical note, as drafted and as approved. The care provider controls it and we process it on the care provider’s written instruction. The second is data about the people who work with the record: authors, reviewers, the DPO and centre heads, plus the care provider’s contract records. This part covers both, in that order.
B.1 What we handle, and in what role
For everything inside the review record we are the care provider’s processor, under a written processing agreement on the care provider’s own template. We act only on the instructions in that agreement and the order form. For the care provider’s contract and account records we are the controller. Nothing inside the record is used for anything other than the review service the care provider ordered.
- The draft and the approved text. The extension reads the draft as the scribe shows it in the consulting-room browser, and the text at the moment the clinician approves it. It sends both to the record with their times. They are read by the two classifiers and by the care provider’s own people with a login to the record, above all the reviewer it names for that centre. Nobody at Corrigenda reads them.
- The consent mark. The clinician’s one-click confirmation, at the start of the consultation, that the patient was informed and agreed to the scribe. If the patient declined, that is logged and nothing more is captured. We don’t record what the patient said, and there is no audio anywhere in the record.
- The scribe version. The version the scribe’s web app reports to the browser. It is saved with each note, so a change in the scribe can be compared with a change in how much clinicians edit. It is a technical label and holds no patient data.
- Twelve months of past notes. At onboarding the care provider’s journal team gives us an export of the approved scribe-drafted notes from the past twelve months. The classifier reads it once to start the review queue. It is kept in the record like any other note, for the same period.
- Verdicts and the correction log. Every verdict the centre’s reviewer records, every correction request sent to an author, the author’s answer and the journal reference that closes it. These hold the names of your staff. The DPO console uses them to produce the monthly report.
- Contract and account records. The care provider’s legal name, organisation number and registered address, the work email of each centre head, DPO and author with a login, the order form and our invoices. We use them to run and invoice the contract.
We hold no audio, and we won’t accept a recording if one is offered. The record starts at the draft.
We hold no login to the journal system. The extension reads the scribe in the browser. It does not read, write or sign in to the journal.
A reviewer sees only the notes of the centres the care provider assigns to their login, and only inside the record, never as an export. Nobody employed or engaged by Corrigenda holds a reviewer login. Our support staff work from account data and capture logs, and do not open the text of a note.
B.2 What we do with it
Everything runs in Stockholm. The review record, the correction log, the DPO console and the contract records run on cloud infrastructure in Stockholm, Sweden. Both classifiers and the per-region training run on cloud GPU capacity we control in Stockholm. We have no second location, and no patient data leaves Sweden.
No hosted model provider. No part of a note is sent to a third-party model API. We run both classifiers ourselves. The only third party involved is the cloud provider named on our subprocessor list, whose infrastructure in Stockholm the service runs on. We engage no reviewers: every person who reads a note in the record works for the care provider, under its own secrecy rules.
An entry is saved once. A note’s entry is saved at the moment of approval, and nobody can edit it afterwards, including us. Verdicts, correction requests, closures and capture failures are added as new entries that point to the note. A mistake in the record is fixed by adding an entry, not by changing the first one.
A failed capture is recorded as a failure. Sometimes the extension can’t read the draft, because the scribe changed its screens or the browser wasn’t covered by the policy. The note then gets an entry saying no draft was captured. We don’t rebuild a draft from the approved text, and the monthly report counts these gaps.
Verdict pairs stay with the region. When the care provider’s reviewer gives a verdict on a flagged passage, we keep the passage, with names and identifiers removed, together with the verdict. One care provider’s pairs are never pooled with another’s. They are used only to train that care provider’s own classifier, and they are exported to the care provider and deleted with the record.
B.3 AI models: where they run and what they learn from
Where models run. All models run on cloud GPU capacity we control in Stockholm, Sweden. One classifier scores passages of an approved note for likely transcription errors. The other labels each edit a clinician made before approving. No part of any note, draft or approved, is sent to a third-party model API, and there is no hosted model provider on our subprocessor list. The per-region training runs on the same capacity in Stockholm. From Q1 2027 the second classifier is a fine-tuned open-weight Swedish language model on that capacity. From Q3 2027 past notes are loaded at onboarding on GPU capacity reserved in advance in Stockholm.
Training. We don’t train any model on the notes in the record, the export of past notes or the correction log, and no third party receives them to train on. There is one narrow, per-region exception. When the care provider’s reviewer gives a verdict on a flagged passage, we keep that passage, with names and identifiers removed, together with the verdict. Those pairs are used only to train that care provider’s own classifier. They are never pooled with another care provider’s, are exported on request, and are deleted with the record.
Where a person decides. The model proposes and a named person at the care provider decides. A passage scoring above 0.7 goes to the review queue of the clinician the care provider has named for that centre. Below that it is not shown, and the note may still be picked in the 2% random sample. The reviewer’s verdict is the decision, and even that changes nothing in the journal: the note’s author makes any correction, under the journal’s own rules. No note is altered, no author is assessed and no patient’s care is affected by an automated decision. This service takes no decision with a legal or similarly significant effect on any person.
B.4 Where the data is kept
All processing and storage is on cloud infrastructure in Stockholm, Sweden. Both classifiers and the per-region training run on cloud GPU capacity we control in Stockholm.
No note, draft or approved, is sent to any hosted model API. No third party runs a model on your data.
The journal remains the record of care and stays where the care provider keeps it. Our review record is evidence kept beside it, not a copy of the journal.
The suppliers that handle data in the service are named on our subprocessor list, which comes with the data processing agreement and which we send to anyone who asks: write to [email protected].
B.5 How long we keep it, and what deleting can’t remove
The review record, including drafts, approved text, changes, verdicts and the correction log: for the length of the contract. It is then exported to the care provider in open formats and deleted from our systems ninety days after the care provider confirms the export, unless the processing agreement sets a different period.
Failed-capture entries and the scribe version history: as long as the record they belong to.
Passage-and-verdict pairs: for the length of the contract, then exported and deleted with the record.
The twelve-month export of past notes: kept as part of the record and deleted with it.
Contract, account and invoice records: for the length of the contract and seven years after, because a Swedish company keeps its accounting records that long.
B.6 Requests from people whose data is in the service
A patient’s request about a note, whether access, correction or objection, goes to the care provider, which controls both the journal and the review record. We help the care provider within five working days and act only on its instruction. A patient who writes to us directly gets the name of the care provider’s data protection officer. The account data we control is contact data for the care provider’s staff. If one of them writes to us, we answer directly on access, correction, deletion and objection, within thirty days.
For everyone
4. Moving data between countries
Corrigenda AB is a company in Sweden, inside the EEA. Section B.4 says where the data in the service is kept. If any personal data we control ever has to leave the EEA, for example because a supplier named on our subprocessor list handles it elsewhere, it is protected by the European Commission’s Standard Contractual Clauses or another safeguard the GDPR accepts. You can ask us for a copy.
5. Security
We protect data in line with the risk. That includes encryption in transit and at rest, access limited to the people and systems that need it, each customer’s data kept separate from every other’s, and a log of every access to production systems.
If a personal data breach affects you, we tell you without undue delay, and at the latest within 36 hours of finding out, with the information you need to meet your own reporting duties.
6. Children
The service is sold to businesses and is not meant for children. We don’t knowingly collect personal data from anyone under 16.
7. Changes to this policy
We may update this policy. If a change matters, we email customers at least 30 days before it takes effect. The version number and date at the top of this page change every time.
8. Contact
Privacy questions and anything else: [email protected]
By post: Corrigenda AB, Östra Hamngatan 16, 411 09 Göteborg, Sweden