SmartArzt
Legal

Privacy Policy

Version 1.1 · Last updated: July 21, 2026

1. About Us

The controller responsible for the personal data described in this policy is:

DataFit Solutions OÜ
Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551, Estonia
Registered at Tartu County Court, registry code 17005668
VAT number: EE102809620
Email: info@datafit-solutions.com

We have not appointed a Data Protection Officer, as we are not required to do so under Art. 37 GDPR. For any questions regarding data protection, please contact us at info@datafit-solutions.com.

2. Scope & Our Role

This Privacy Policy applies to all services offered by DataFit Solutions OÜ under the SmartArzt brand:

  • Web application at app.smartarzt.de
  • SmartArzt Audio Recorder Chrome Extension
  • Public API for third-party integrations

We act in two distinct roles, and this policy is structured accordingly:

  • Part A - Personal data we process as controller: the account, contact, billing and technical data of our users (physicians and healthcare institutions), for which we determine the purposes and means of processing.
  • Part B - Patient data we process as processor: audio recordings and medical documents that healthcare institutions process via SmartArzt, for which we act solely as a data processor under Art. 28 GDPR on the controller's instructions.

SmartArzt is intended for medical professionals (physicians and healthcare institutions). For patient data processed via SmartArzt, the using healthcare institution is the data controller under GDPR, and DataFit Solutions OÜ acts as a data processor (see Part B).

Part A - Personal Data We Process as Controller

This part describes the personal data for which DataFit Solutions OÜ is the controller, primarily the account and contact data of our users.

3. Data We Collect

3.1 Account & Contact Data

When you register for and use the service, we process:

  • Name and email address
  • Authentication data (managed by Auth0)
  • Usage and billing data (number of recordings processed, quota usage)

Providing this account information is necessary to create and maintain your account and to enter into and perform the contract for the SmartArzt service. Without it, we cannot provide the service.

3.2 Technical Data

  • IP addresses and access times (in server logs)
  • Device information and browser type
  • Settings stored locally in the Chrome Extension (API key, recording settings)

4. How We Use This Data

  • Authentication and authorisation of users
  • Usage accounting and quota management
  • Detection and prevention of abuse and security incidents
  • Responding to support requests

5. Legal Basis for Processing (GDPR)

  • Contract performance (Art. 6(1)(b) GDPR): Account, authentication, and usage and billing data.
  • Legitimate interests (Art. 6(1)(f) GDPR): Server logs, security monitoring, and operation of the service. Our legitimate interests include maintaining the security and reliability of our services, preventing fraud and abuse, and enforcing our contractual rights.
  • Legal obligation (Art. 6(1)(c) GDPR): Where required by applicable law, e.g. statutory retention of billing records.

6. Recipients

We do not sell your data or share it with third parties for commercial purposes. Depending on the processing activity, the categories of recipients to whom personal data may be disclosed are:

  • Cloud hosting and infrastructure providers
  • Authentication providers
  • Competent public authorities, where required by law

The specific sub-processors we engage across both roles are listed in the General Information section below.

7. Data Retention

  • Account information: Retained for the duration of the contractual relationship and fully deleted within 30 days of contract termination.
  • Billing records: Retained for up to 7 years where required to comply with statutory accounting and tax obligations, and then deleted.
  • Support emails: Retained for the duration of the contractual relationship and deleted thereafter.
  • Authentication records: Identity data is retained for the duration of the account. Authentication and access logs are retained for 365 days and then deleted.
  • Server logs: Technical access logs are retained for 365 days and then deleted.

Retention of patient data processed as a processor is described in Part B.

8. Data Security

  • All data encrypted in transit via TLS 1.2+
  • Data at rest encrypted with AES-256 via AWS KMS
  • Infrastructure hosted in private AWS networks (C5-certified) within the EU, with no direct internet exposure
  • Access controls following least-privilege principles
  • Regular security reviews
  • Security controls based on ISO/IEC 27001 practices

These security measures apply to all data we process, including patient data under Part B. Additional information regarding our security measures is available in our Trust Center.

9. International Data Transfers

All data is processed and stored exclusively within the European Economic Area (EEA). No transfers outside the EEA take place.

Part B - Patient Data We Process as Processor

This part describes patient data that healthcare institutions process via SmartArzt. For this data, the using healthcare institution is the controller and DataFit Solutions OÜ acts solely as a processor under Art. 28 GDPR.

10. Patient Data & Our Role as Processor

When users upload audio recordings and related documents, these are processed on behalf of the healthcare institution acting as controller. This includes:

  • Audio recordings
  • Transcriptions of recordings
  • AI-generated medical letters and documents
  • Uploaded context documents (e.g. lab results, PDFs)

This data may contain patient data (special categories of personal data under Art. 9 GDPR). DataFit Solutions OÜ processes such data solely on the instructions of the using healthcare institution, as a data processor. Patient data processed through SmartArzt is provided by the healthcare institution using the service.

For any personal data contained in audio or documents processed via SmartArzt, the legal basis is determined solely by the data controller (the using healthcare institution). DataFit Solutions OÜ does not determine the purpose or means of processing. Where processing supports medical diagnosis or the provision of health care, Art. 9(2)(h) GDPR typically applies; the controller determines the applicable Article 9 condition.

11. Retention of Patient Data

  • Web application: Medical documents are retained for the duration of the contractual relationship and fully deleted within 30 days of contract termination.
  • Public API: Audio uploads, transcriptions, and generated documents are automatically deleted no later than 48 hours after processing.

12. End Users Whose Data Appears in Recordings

If you are an end user (e.g. a patient) whose personal data may be contained in audio or documents processed via SmartArzt, your data controller is the healthcare institution using SmartArzt. Please contact them directly to exercise your rights. Where we process patient data solely on behalf of healthcare institutions as a processor, the transparency obligations under Articles 13 and 14 GDPR are fulfilled by the relevant healthcare institution acting as controller.

General Information

13. Sub-processors

To deliver the service we engage the following sub-processors. Each is bound by a data processing agreement under Art. 28 GDPR, including EU standard contractual clauses where applicable, and processing of your data takes place within the EU/EEA:

  • Amazon Web Services (AWS): cloud hosting and storage (Part A and Part B)
  • Auth0 by Okta: user authentication (Part A)
  • Speechmatics: speech recognition (Part B)
  • Google Cloud Platform: cloud computing services (Part B)

A current list is also available on request at info@datafit-solutions.com.

14. Your Rights under GDPR

As a data subject you have the following rights in respect of the data we process about you as controller:

  • Access (Art. 15 GDPR): What data we process about you
  • Rectification (Art. 16 GDPR): Correction of inaccurate data
  • Erasure (Art. 17 GDPR): Deletion of your data
  • Restriction (Art. 18 GDPR): Restriction of processing
  • Portability (Art. 20 GDPR): Receipt of your data in a machine-readable format
  • Objection (Art. 21 GDPR): Objection to processing
  • Withdrawal of consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR.

To exercise your rights over data we process directly, contact us at info@datafit-solutions.com. We will respond within 30 days. If your data appears in patient recordings, please see Part B and contact the relevant healthcare institution.

You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement. The supervisory authority for DataFit Solutions OÜ is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee.

15. Cookies

We use only strictly necessary cookies and similar technologies required for authentication, security and the operation of the service. We do not use advertising or analytics cookies on our website. Because these cookies are strictly necessary to provide the service, no cookie consent is required for them.

16. Changes to This Policy

We may update this Privacy Policy from time to time. The version number and "last updated" date at the top of this page reflect the latest revision. For material changes, users will be notified by email. Previous versions of this Privacy Policy are available on request at info@datafit-solutions.com.

17. Contact

DataFit Solutions OÜ
Email: info@datafit-solutions.com
More information: Trust Center