🔒 Privacy Policy

How we protect and handle your data

Last Updated: November 17, 2025

Effective Date: November 17, 2025

Our Privacy Commitment

HearScribe is built on a zero patient data storage architecture. We never store, transmit, or have access to patient-identifiable information, clinical notes, audio recordings, or transcriptions. This Privacy Policy explains what limited data we do collect and how we protect it.

1. Introduction

The Hearing Lab Store Ltd ("we," "us," "our") operates HearScribe, an AI-powered clinical documentation platform for hearing healthcare professionals. This Privacy Policy explains how we collect, use, protect, and share information in compliance with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018.

By using HearScribe, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our service.

2. Data Controller Information

Data Controller: The Hearing Lab Store Ltd
Company Number: 13464826
VAT Number: GB384197168
Contact: contact@hearscribe.com

For data protection inquiries, contact us at contact@hearscribe.com with "Data Protection" in the subject line.

3. Zero Patient Data Storage Architecture

Critical Privacy Feature

HearScribe employs a unique zero patient data storage architecture. ALL patient-identifiable information, clinical notes, audio recordings, and transcriptions remain EXCLUSIVELY in your browser's local memory and are NEVER transmitted to or stored on our servers.

3.1 What This Means for Patient Privacy

When you use HearScribe:

3.2 Data Controller Roles

Under this architecture:

4. Global Healthcare Privacy Compliance

Worldwide Compliance Through Zero Data Architecture

Because HearScribe never stores patient data, we automatically comply with healthcare privacy regulations worldwide. Our zero patient data architecture eliminates compliance complexity across jurisdictions.

4.1 Regulations We Comply With

HearScribe's zero patient data storage architecture ensures automatic compliance with:

4.2 Why This Matters for International Practices

If you practice across multiple jurisdictions or treat patients from different countries:

4.3 Competitive Advantage

Most healthcare SaaS platforms struggle with multi-jurisdiction compliance. HearScribe eliminates this complexity entirely by never storing the regulated data in the first place. You maintain complete control and ownership of patient records while we handle only your non-clinical account information.

5. Information We Collect

5.1 Account Information (We DO Collect)

When you create a HearScribe account, we collect:

5.2 Usage Metadata (We DO Collect)

We collect limited metadata about platform usage:

5.3 Patient Data (We DO NOT Collect)

Never Stored or Transmitted

We explicitly DO NOT collect, store, transmit, or have access to: patient names, patient identifiers, clinical notes, audio recordings, transcriptions, health information, diagnosis data, treatment plans, or any patient-identifiable information.

5.4 Technical Data

Standard web hosting and security data:

6. How We Use Your Information

6.1 Account Information Usage

We use your account information to:

6.2 AI Processing

When you generate clinical notes:

6.3 Communications

We may contact you via email for:

You can opt out of non-essential communications through your account settings.

7. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases:

Data Type Legal Basis Purpose
Account Information Contract Performance Provide HearScribe service
Payment Data Contract Performance Process subscription payments
Usage Metadata Legitimate Interest Improve service, prevent abuse
Marketing Communications Consent Send promotional emails (opt-in)
Security Logs Legitimate Interest Fraud prevention, security

8. Third-Party Services

HearScribe integrates with the following third-party services:

8.1 Supabase (Database & Authentication)

8.2 Stripe (Payment Processing)

8.3 Google Gemini API (AI Generation)

8.4 Netlify (Hosting)

9. Data Retention

9.1 Active Accounts

9.2 Cancelled Accounts

9.3 Patient Data

Since patient data never reaches our servers, we cannot and do not retain it. YOU are responsible for backing up and retaining your clinical records according to your professional and legal obligations.

10. Your Data Protection Rights (GDPR)

Under UK GDPR, you have the following rights regarding your personal data:

10.1 Right of Access

You can request a copy of all personal data we hold about you. Contact contact@hearscribe.com to request your data.

10.2 Right to Rectification

You can update your account information at any time through your account settings or by contacting us.

10.3 Right to Erasure ("Right to be Forgotten")

You can request deletion of your account and all associated data. Note: Billing records must be retained for 7 years per UK tax law.

10.4 Right to Data Portability

You can request your account data in a machine-readable format. Contact us to initiate a data export.

10.5 Right to Object

You can object to processing based on legitimate interests. We will cease processing unless we have compelling legitimate grounds.

10.6 Right to Restrict Processing

You can request restriction of processing in certain circumstances. Contact us to discuss your specific situation.

10.7 Right to Withdraw Consent

Where processing is based on consent, you can withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.

10.8 Right to Lodge a Complaint

You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):

ICO: ico.org.uk
Phone: 0303 123 1113

11. Data Security

11.1 Technical Security Measures

11.2 Organizational Security Measures

11.3 Zero Patient Data Storage

Our most significant security measure is architectural: by never storing patient data, we eliminate the risk of patient data breaches entirely. Patient information cannot be compromised because it never exists on our servers.

12. Data Breach Notification

In the unlikely event of a data breach affecting your account information:

Note: Patient data breaches cannot occur in HearScribe because we never store patient data.

13. International Data Transfers

Your account data is stored within the UK/EU through Supabase. Some third-party services (Stripe, Google Gemini) may process data internationally. These services are:

14. Children's Privacy

HearScribe is designed for professional healthcare use only. We do not knowingly collect information from individuals under 18 years of age. If you believe we have inadvertently collected such information, contact us immediately for deletion.

15. Cookies and Tracking

HearScribe uses minimal cookies essential for platform functionality. We do NOT use:

For complete cookie information, see our Cookie Policy.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be:

Your continued use of HearScribe after changes constitutes acceptance of the updated Privacy Policy.

17. Contact Us

For privacy-related inquiries, data access requests, or to exercise your GDPR rights:

Email: contact@hearscribe.com
Subject Line: "Data Protection Request"

The Hearing Lab Store Ltd
Company Registration Number: 13464826
VAT Number: GB384197168

We will respond to all requests within 30 days as required by UK GDPR.

← Back to Account