Privacy Policy
How Devinote processes your data (GDPR).
This privacy policy explains how personal data is processed when you use Devinote at https://med.devinote.de.
1. Controller
Devontra KG
Freigrafendamm 11
44803 Bochum
Email: info@devontra.com
2. Purpose
Devinote is a SaaS tool supporting clinical documentation (live transcription, text summary, export). Clinical responsibility and patient consent remain with the healthcare professional using the product.
3. Data categories
- Account data: email, display name, authentication, roles, seats, subscription status.
- Session metadata: session label (e.g. Transcript_yyyyMMdd_HHmmss), professional name, language, times, source (Live/Text), export status — without storing transcript text in the application database.
- Content for processing: audio (as a live stream, or as a recording of the session transmitted as a file after the visit and not stored) or pasted text is sent to processors for transcription/summary (below) and is not persisted as clinical text in the Devinote database.
- Payment data: handled by Stripe; we store subscription/invoice metadata, not full card numbers.
- Technical data: auth events, security-related IP/session signals, essential cookies.
4. Transcripts and notes
Clinical transcript text and AI notes are not stored permanently in the Devinote database. Live transcripts may be held temporarily in the browser (sessionStorage) and are cleared when the tab closes. Practices should export PDF/TXT for retention.
5. Processors / services
- Hosting: application hosting (including Coolify-based infrastructure), database and TLS.
- Microsoft Azure Speech: speech-to-text, either as a live stream or by transmitting the session recording after the visit; Devinote does not store the recording.
- Microsoft Azure OpenAI: structured documentation drafts from text.
- Stripe: payments, subscriptions, customer portal.
- Transactional email (e.g. Resend): confirmations, invites, support.
We use industry-standard data processing / privacy terms with these providers (including SCCs where required for third-country transfers). The Azure region follows production configuration.
6. Legal bases (GDPR)
- Art. 6(1)(b) — contract performance (account, licence, support).
- Art. 6(1)(f) — legitimate interest in secure operation and abuse prevention.
- Art. 6(1)(a) — consent where separately obtained.
- Art. 9 — special categories: processed only to support documentation by professionals; the practice ensures a lawful basis toward patients.
7. Cookies
We use only essential cookies / similar storage, including authentication, antiforgery, UI language/theme, and the cookie notice flag. No third-party marketing cookies.
8. Retention
Account and subscription data for the contract term and statutory retention. Auth/technical logs only as long as needed for security. Browser sessionStorage ends with the tab.
9. Your rights
Access, rectification, erasure, restriction, portability, objection, and complaint to a supervisory authority. Contact: info@devontra.com.
10. Security
HTTPS in transit; authenticated access; licence/seat controls. Absolute security cannot be guaranteed.
11. Version
Last updated: August 2026. We will update this page when material changes occur.