Zurück

Privacy Policy

Information on the processing of personal data under the revised Swiss Federal Act on Data Protection (revFADP)

Letzte Aktualisierung: 13.05.2026

As of 2026-05-13. This privacy policy informs you, as a user of MiraScribe and as an affected patient (data subject), about which personal data we process, for which purposes, and which rights you are entitled to under the revised Swiss Federal Act on Data Protection (revFADP). Where the GDPR additionally applies (processing of data of data subjects in the EU), those provisions apply in addition.

1. Controller

The controller within the meaning of Art. 5 lit. j revFADP is:

MiraNext GmbH, business address Innsbrucker Bundesstraße 83a, 5020 Salzburg, Austria. FN 614242 y, VAT ATU 78451209.

Where a Swiss representative is appointed under Art. 14 revFADP: [Placeholder — name and address of the Swiss representative].

General enquiries: support@miranext.ai.

2. Data Protection Advisor / Contact

You can reach us with data protection questions at: support@miranext.ai. Where a data protection advisor is appointed under Art. 10 revFADP, the name will be added before placing on the market.

3. Categories of Data Processed

We process only the categories of data required to operate MiraScribe:

  • User account data: name, professional email address, job title, organisational affiliation, authentication features.
  • Consultation metadata: date, time, duration, template used, selected language.
  • Audio: live stream of the consultation. Audio is not stored permanently (see retention period).
  • Transcripts: full-text transcription of the consultation.
  • Structured notes: clinical documentation generated from the transcript (e.g. history, findings, plan, ICD-10 suggestions).
  • Health data qualify as sensitive personal data under Art. 5 lit. c revFADP and are subject to heightened protection.
  • Usage data: device and browser identifiers, IP address, diagnostic data to ensure stability.

4. Purposes and Grounds for Processing

Processing is carried out for the following purposes. The revFADP requires compliance with the processing principles (Art. 6 revFADP); processing of sensitive personal data in particular requires a justification ground under Art. 31 revFADP (e.g. consent, overriding interest, statutory basis):

  • Transcription and structuring of medical consultations and processing of health data: based on the data subject's consent or an overriding processing ground (Art. 31 revFADP), in conjunction with professional secrecy rules (Art. 321 Swiss Criminal Code).
  • Contract performance towards users and institutions: to perform the contract with the data subject (Art. 31 para. 2 lit. a revFADP).
  • Compliance with legal obligations (e.g. retention duties, MedDO market surveillance): statutory basis.
  • Security, abuse prevention, quality assurance and product improvement in pseudonymised form: overriding legitimate interest of the controller.

5. Recipients and Processors

To provide the service we engage the following processors (Art. 9 revFADP). A complete, up-to-date list of sub-processors is provided on request:

  • Google Cloud Platform — hosting, Postgres database and Vertex AI inference; processing in the EU (europe-west3 Frankfurt, europe-west4 Netherlands).
  • Deepgram — speech-to-text provider; processing via the EU endpoint.
  • Cerebras Systems — language-model inference for structured notes; processing in the USA (see disclosure abroad).
  • Vertex AI — language-model inference within the EU.
  • Resend, a Nodemailer-compatible SMTP provider — transactional emails.
  • Stripe — payment processing towards institutions.

6. Disclosure of Personal Data Abroad

Disclosure abroad occurs in particular to EU states (adequate level of protection within the meaning of Art. 16 revFADP and the DPO country list) and to Cerebras Systems (USA).

Where a recipient state does not ensure an adequate level of protection (e.g. the USA outside the applicable data protection framework), we base the disclosure on standard contractual clauses recognised by the FDPIC (Art. 16 para. 2 lit. d revFADP) and on supplementary technical safeguards (encryption, pseudonymisation). The relevant documentation is provided on request.

7. Retention Period

Audio is not persisted. The audio stream is forwarded live to the STT provider and discarded after the transcript has been created.

Transcripts and structured notes are stored for the term of the contract and deleted within 30 days after the end of the contract, unless statutory retention obligations require otherwise.

Account data are deleted once they are no longer required for the contract, at the latest after expiry of the relevant limitation periods (Art. 127 CO).

Backup data are retained on a rolling 35-day basis and then cryptographically deleted.

8. Rights of Data Subjects

Under the revFADP you have in particular the following rights vis-à-vis the controller:

  • Right of access regarding the processing of your personal data (Art. 25 revFADP),
  • Right to rectification of inaccurate personal data (Art. 32 revFADP),
  • Right to data portability / handover of data (Art. 28 revFADP),
  • Right to request the deletion or destruction of personal data (Art. 32 revFADP),
  • Right to object to processing and to withdraw a given consent with effect for the future.

9. Supervisory Authority

You have the right to contact the competent supervisory authority.

Competent in Switzerland: Federal Data Protection and Information Commissioner (FDPIC / EDÖB), Feldeggweg 1, 3003 Bern — https://www.edoeb.admin.ch.

10. Obligation to Provide Data

Providing your account data is necessary for the performance of the contract. Without these data we cannot grant you access to MiraScribe.

Recording the consultation is voluntary; however, the core function of MiraScribe cannot be used without recording.