Zurück

Privacy Policy (Germany)

Information on the processing of personal data pursuant to Art. 13 and 14 GDPR in conjunction with the BDSG

Letzte Aktualisierung: 13.05.2026

As of 2026-05-13. This privacy policy informs you, as a user of MiraScribe and as an affected patient (data subject), about which personal data we process, for which purposes, on which legal basis, and which rights you are entitled to. It applies to use in Germany and supplements the GDPR with the provisions of the German Federal Data Protection Act (BDSG).

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

MiraNext GmbH, business address [Placeholder — registered business address], 5020 Salzburg, Austria. Commercial register no. FN 614242 y, VAT ID ATU 78451209.

A domestic representative or authorised recipient for service in Germany is to be stated where applicable: [Placeholder — German representative, if appointed].

General enquiries: support@miranext.ai.

2. Data Protection Officer

Insofar as an obligation to designate a Data Protection Officer exists pursuant to Art. 37 GDPR in conjunction with § 38 BDSG, you can reach our Data Protection Officer at: support@miranext.ai.

Name and contact details of the appointed person: [Placeholder — name and contact details of the Data Protection Officer]. This information will be added before placing on the market.

3. Categories of Data Processed

We process exclusively the categories of data required to operate MiraScribe:

  • User account data: name, professional email address, job title, organisational affiliation, authentication credentials.
  • Consultation metadata: date, time, duration, template used, selected language.
  • Audio: live stream of the consultation. Audio is not stored permanently (see Retention Period).
  • Transcripts: full-text transcription of the consultation.
  • Structured notes: medical documentation generated from the transcript (e.g. history, findings, plan, ICD-10 suggestions).
  • Health data: special categories of personal data pursuant to Art. 9(1) GDPR arising from audio, transcript, and structured notes.
  • Usage data: device and browser identifiers, IP address, diagnostic data for ensuring stability.

4. Purposes of Processing and Legal Bases

Processing is carried out for the following purposes on the legal bases stated:

  • Transcription and structuring of medical consultations as well as processing of health data (special categories pursuant to Art. 9 GDPR): Art. 9(2)(h) GDPR in conjunction with § 22(1) no. 1(b) BDSG (administration of systems and services in the healthcare sector) and in conjunction with the medical duty of confidentiality (§ 203 German Criminal Code (StGB)).
  • Appropriate and specific measures to safeguard special categories of data pursuant to § 22(2) BDSG (technical and organisational measures, access restrictions, encryption, pseudonymisation).
  • Performance of the contract with users and institutions: Art. 6(1)(b) GDPR.
  • Compliance with legal obligations (e.g. commercial- and tax-law retention obligations under the German Commercial Code (HGB) and Fiscal Code (AO), MDR market surveillance): Art. 6(1)(c) GDPR.
  • Security, abuse prevention, quality assurance, and product improvement in pseudonymised form: Art. 6(1)(f) GDPR (legitimate interest).

5. Recipients and Processors

To provide the service, we use the following processors (Art. 28 GDPR). A complete and up-to-date list including sub-processors is made available on request:

  • Google Cloud Platform — hosting, Postgres database, and Vertex AI inference; processing within the EU (europe-west3 Frankfurt, europe-west4 Netherlands).
  • Deepgram — speech-to-text provider; processing via the EU endpoint.
  • Cerebras Systems — language-model inference for structured notes; processing in the USA (see Transfers to Third Countries).
  • Vertex AI — language-model inference within the EU.
  • Resend, a Nodemailer-compatible SMTP provider — transactional emails.
  • Stripe — payment processing towards institutions.

6. Transfers to Third Countries

A transfer to third countries takes place exclusively to Cerebras Systems (USA). This transfer is based on the Standard Contractual Clauses pursuant to Implementing Decision (EU) 2021/914 (SCCs).

In addition, we carry out a documented Transfer Impact Assessment (TIA) in accordance with EDPB Recommendation 01/2020 and implement supplementary technical safeguards (encryption, pseudonymisation). The TIA is made available on request.

7. Retention Period

Audio is not persisted. The audio stream is forwarded live to the STT provider and discarded after the transcript has been created.

Transcripts and structured notes are stored for the duration of the contract and deleted within 30 days after the end of the contract, unless statutory retention obligations apply.

Account data is deleted as soon as it is no longer required for the contract, at the latest upon expiry of the applicable limitation periods under the German Civil Code (BGB).

Backup data is retained on a rolling basis for 35 days and subsequently deleted cryptographically.

8. Rights of Data Subjects

You are entitled to the following rights vis-à-vis the controller:

  • Right of access (Art. 15 GDPR),
  • Rectification of inaccurate data (Art. 16 GDPR),
  • Erasure (Art. 17 GDPR),
  • Restriction of processing (Art. 18 GDPR),
  • Data portability (Art. 20 GDPR),
  • Objection to processing based on legitimate interests (Art. 21 GDPR),
  • Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR).

9. Right to Lodge a Complaint with the Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). In Germany, competence is generally determined by the federal state (Land) of the controller or of your habitual residence.

Competent supervisory authority: [Placeholder — competent State Data Protection Authority, e.g. the State Commissioner for Data Protection and Freedom of Information of the relevant federal state].

An overview of all supervisory authorities can be found at the Federal Commissioner for Data Protection and Freedom of Information (BfDI), Graurheindorfer Str. 153, 53117 Bonn.

10. Obligation to Provide Data

Providing your account data is required for the performance of the contract. Without this data, we cannot grant you access to MiraScribe.

Recording the consultation is voluntary; however, without a recording the core function of MiraScribe cannot be used.