Data practices

This page summarises, in plain language, how Emedis Cloud handles patient and clinical data in the release being prepared for go-live. Some measures described here are built and tested but not yet deployed in every environment. It is a practical overview — not a contract. A full Privacy Policy and a GDPR Article 28 Data Processing Agreement are being prepared with legal counsel; contact us to discuss data-protection terms before onboarding a practice.

Where records are stored

Consultation records and the encrypted patient identity are stored on the server of Emedis' hosting provider (see the sub-processors page). The location of the production environment has not been decided: Emedis proposes a data centre in the European Union, to be agreed with the customer. The current pilot runs on a server in the United Kingdom. Consultation audio is not stored.

Patient identifiers

The patient's name, date of birth, ID or ARC number and phone numbers are encrypted by the Emedis server (AES-256-GCM, with a separate key for each organisation) before they are stored. The keys are kept outside the database. The server decrypts the identity only for users who are allowed to see that patient. This is not end-to-end encryption: the server can read the identity when an authorised user opens the record. A keyed hash (blind index) lets the system find duplicate patients without storing the identifier in clear.

AI processing

To transcribe the consultation and to draft the record, notes and forms, the audio and the text generated from it are processed by open AI models that Emedis runs on GPU servers rented from a GPU hosting provider. Before text goes to the language model, the patient's own identifiers are removed on the server, and if that cannot be done nothing is sent. Audio and document images cannot be redacted; they are processed as captured, and audio is not stored. Other people named in a consultation can remain in the text, so it is treated as personal data. The current release uses no external language-model provider. Speech recognition by Deepgram (EU endpoint) is a fallback, used only if the customer has enabled it. Each provider, with its role and location, is listed on our sub-processors page.

Who can see clinical content

Doctors see their own patients. A practice manager can give a doctor or a nurse access to a patient list or to a single patient; such changes are recorded in the audit trail. Nurses see only what they were granted. Managers do not see clinical content unless they are also treating clinicians. Emedis platform administrators are not meant to read clinical content; the technical restrictions on their access are being completed before go-live. Access is enforced by row-level security in the database.

Clinician responsibility

All AI-generated content must be reviewed and approved by a qualified clinician before any clinical decision is made. Emedis Cloud is a documentation and decision-support aid and is not a regulated medical device.

Retention, rights and certifications

Data-retention schedules, data-subject-rights workflows (access, rectification, erasure, portability) and formal security certifications are being finalised. Emedis Cloud is in an early-access pilot. Contact us for the current status before relying on any specific commitment.