Zurück

Privacy Policy

Information on the processing of personal data pursuant to Art. 13 and 14 GDPR

Letzte Aktualisierung: 13.05.2026

As of 2026-05-13. This privacy policy informs you, as a user of MiraScribe and as an affected patient (data subject), about which personal data we process, for which purposes, on which legal basis, and which rights you are entitled to. It applies to use in Austria and supplements the GDPR with the provisions of the Austrian Data Protection Act (DSG).

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

MiraNext GmbH, business address [Placeholder — registered business address], 5020 Salzburg, Austria. Commercial register no. FN 614242 y, VAT ID ATU 78451209.

General enquiries: support@miranext.ai.

2. Data Protection Officer

You can reach our Data Protection Officer at: support@miranext.ai. The name of the appointed person will be added before placing on the market.

3. Categories of Data Processed

We process exclusively the categories of data required to operate MiraScribe:

  • User account data: name, professional email address, job title, organisational affiliation, authentication credentials.
  • Consultation metadata: date, time, duration, template used, selected language.
  • Audio: live stream of the consultation. Audio is not stored permanently (see Retention Period).
  • Transcripts: full-text transcription of the consultation.
  • Structured notes: medical documentation generated from the transcript (e.g. history, findings, plan, ICD-10 suggestions).
  • Usage data: device and browser identifiers, IP address, diagnostic data for ensuring stability.

4. Purposes of Processing and Legal Bases

Processing is carried out for the following purposes on the legal bases stated:

  • Transcription and structuring of medical consultations as well as processing of health data (special categories pursuant to Art. 9 GDPR): Art. 9(2)(h) GDPR in conjunction with national professional-secrecy provisions (e.g. § 54 Austrian Medical Practitioners Act (ÄrzteG); § 203 German Criminal Code (StGB)).
  • Performance of the contract with users and institutions: Art. 6(1)(b) GDPR.
  • Compliance with legal obligations (e.g. commercial- and tax-law retention obligations, MDR market surveillance): Art. 6(1)(c) GDPR.
  • Security, abuse prevention, quality assurance, and product improvement in pseudonymised form: Art. 6(1)(f) GDPR (legitimate interest).

5. Recipients and Processors

To provide the service, we use the following processors (Art. 28 GDPR). A complete and up-to-date list including sub-processors is made available on request:

  • Google Cloud Platform — hosting, Postgres database, and Vertex AI inference; processing within the EU (europe-west3 Frankfurt, europe-west4 Netherlands).
  • Deepgram — speech-to-text provider; processing via the EU endpoint.
  • Cerebras Systems — language-model inference for structured notes; processing in the USA (see Transfers to Third Countries).
  • Vertex AI — language-model inference within the EU.
  • Resend, a Nodemailer-compatible SMTP provider — transactional emails.
  • Stripe — payment processing towards institutions.

6. Transfers to Third Countries

A transfer to third countries takes place exclusively to Cerebras Systems (USA). This transfer is based on the Standard Contractual Clauses pursuant to Implementing Decision (EU) 2021/914 (SCCs).

In addition, we carry out a documented Transfer Impact Assessment (TIA) in accordance with EDPB Recommendation 01/2020 and implement supplementary technical safeguards (encryption, pseudonymisation). The TIA is made available on request.

7. Retention Period

Audio is not persisted. The audio stream is forwarded live to the STT provider and discarded after the transcript has been created.

Transcripts and structured notes are stored for the duration of the contract and deleted within 30 days after the end of the contract, unless statutory retention obligations apply.

Account data is deleted as soon as it is no longer required for the contract, at the latest upon expiry of the applicable limitation periods (German BGB / Austrian ABGB).

Backup data is retained on a rolling basis for 35 days and subsequently deleted cryptographically.

8. Rights of Data Subjects

You are entitled to the following rights vis-à-vis the controller:

  • Right of access (Art. 15 GDPR),
  • Rectification of inaccurate data (Art. 16 GDPR),
  • Erasure (Art. 17 GDPR),
  • Restriction of processing (Art. 18 GDPR),
  • Data portability (Art. 20 GDPR),
  • Objection to processing based on legitimate interests (Art. 21 GDPR),
  • Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR).

9. Right to Lodge a Complaint with the Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).

The authority with primary competence is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb@dsb.gv.at); in Germany, the competent State Data Protection Authority (Landesdatenschutzbehörde) applies, a list of which can be found at the Federal Commissioner for Data Protection and Freedom of Information (BfDI).

10. Obligation to Provide Data

Providing your account data is required for the performance of the contract. Without this data, we cannot grant you access to MiraScribe.

Recording the consultation is voluntary; however, without a recording the core function of MiraScribe cannot be used.