1. Data Controller
CliniNote Sp. z o.o. ("the Company," "we," "us," or "our") (Plac Bankowy 2, 00-102 Warsaw, Poland) is the data controller for personal data processed in connection with getclininote.com and the CliniNote clinical NLP service. For any data-protection matter, including to exercise the rights described below, contact us at [email protected].
2. About CliniNote and the Data We Process
The Company operates a clinical NLP platform that structures free-text electronic health record notes into research-ready datasets for clinical research and real-world evidence teams. The platform extracts diagnoses (ICD-10), medications (NDC), procedures (CPT), laboratory values (LOINC codes), and clinical timelines from notes submitted by institutional customers.
This means the Company handles two distinct categories of personal data, in two distinct roles:
- Website and contact data (controller role): identity and contact information submitted through getclininote.com, for example through early-access request or demo request forms.
- Clinical note content (processor role): electronic health record content submitted by institutional customers through the CliniNote platform. Such content typically constitutes health data within the meaning of Article 9 GDPR. In this context the Company acts as a data processor under Article 28 GDPR, operating under a data processing agreement with each institutional customer. Institutional customers remain the data controllers for the patient data they submit and are responsible for establishing the appropriate legal basis for that processing.
This Privacy Policy addresses the Company's controller-role processing. Institutional customers who wish to understand how the Company handles clinical note content as a processor should request the Company's data processing addendum at [email protected].
3. Personal Data We Process as Controller
In its data controller capacity, the Company processes the following categories of personal data:
- Identity and contact data you submit (name, email address, phone number, employer name, job role);
- Communications content (messages, inquiry text, demo request details);
- Technical data collected automatically (IP address, browser type, operating system, pages visited, session identifiers);
- Usage and analytics data, where you have given consent.
The Company does not use clinical note content submitted through the platform to train, fine-tune, or otherwise improve its NLP models. Extraction runs are processed in isolated per-organisation environments. Clinical note content is not retained beyond the customer's active session unless the customer explicitly saves the extraction output within the platform.
4. Purposes and Legal Bases (Article 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Responding to your inquiries and demo requests | Pre-contract steps or legitimate interest (Art. 6(1)(b)/(f)) |
| Operating and securing the Service, including platform authentication and audit logging | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance (including record-keeping obligations) | Legal obligation (Art. 6(1)(c)) |
| Email communications about CliniNote updates or features (where applicable) | Consent (Art. 6(1)(a)) |
| Analytics cookies to measure website usage | Consent (ePrivacy Directive and Art. 6(1)(a)) |
Where the Company processes health data as a processor on behalf of an institutional customer, the legal basis for that processing is established by the customer under Article 9 GDPR, typically Article 9(2)(j) (scientific research or statistical purposes) or Article 9(2)(h) (healthcare provision) in combination with applicable national law.
5. Recipients and Transfers
Personal data is shared only with processors acting on the Company's behalf under Article 28 GDPR data-processing agreements. These include infrastructure hosting providers (servers located within the EU, primarily Poland and Frankfurt, Germany), transactional email delivery, and, where consented, web analytics services.
The Company does not sell personal data. Clinical note content submitted by institutional customers is not shared with any third party other than the infrastructure processors required to deliver the extraction service, and then only under strict contractual restrictions.
Where any data transfer outside the EU/EEA is required, the Company relies on Standard Contractual Clauses (Article 46 GDPR) and carries out a documented transfer impact assessment as required following the Schrems II ruling of the Court of Justice of the European Union.
6. Retention
We retain personal data only as long as necessary for the purposes described. Specific periods:
- Early-access and demo inquiry data: retained for 24 months from the date of last contact;
- Contracted customer account data: retained for the duration of the contract and for a period of 5 years thereafter, in accordance with Polish statutory accounting requirements;
- Server and platform access logs: retained for 90 days;
- Clinical note content processed as a processor: subject to the retention terms agreed with the institutional customer in the data processing agreement. By default, raw uploaded content is deleted within 30 days of extraction completion unless the customer saves output explicitly.
7. Your GDPR Rights
- Right of access (Art. 15): confirm whether we process your data and obtain a copy;
- Right to rectification (Art. 16);
- Right to erasure, or the right to be forgotten (Art. 17), subject to limited exceptions;
- Right to restriction of processing (Art. 18);
- Right to data portability (Art. 20);
- Right to object (Art. 21), including to direct marketing without further conditions;
- Right not to be subject to automated decision-making (Art. 22). The Company does not engage in automated decision-making with legal effects on individuals.
To exercise any right, email [email protected]. The Company responds within one month, extendable by two further months for complex requests. Where a request relates to data processed on behalf of an institutional customer, the Company will direct the request to that customer as the relevant data controller.
8. Right to Lodge a Complaint
You have the right to lodge a complaint with a national supervisory authority. The Company's lead supervisory authority is the President of the Personal Data Protection Office (UODO) in Poland (uodo.gov.pl). You may also contact the supervisory authority in your country of residence or place of work. A full list of EU/EEA authorities is available at edpb.europa.eu.
9. Cookies
See the Cookie Policy for details on what cookies the Company uses and how consent is managed. Non-essential cookies are not set without your prior consent, in accordance with the ePrivacy Directive.
10. Security
The Company implements technical and organisational measures appropriate to the risk. These include TLS encryption in transit, AES-256 encryption at rest, per-organisation data isolation, role-based access controls, and regular security review. Because the Company handles clinical data, its security programme follows HIPAA-adjacent design principles: encryption, access control, and audit logging aligned with what healthcare institution partners require. These are design principles, not a certification claim.
11. Changes
Material changes to this policy will be reflected by an updated "Last updated" date at the top of this page. Where required by applicable law, the Company will request renewed consent.
12. Contact
CliniNote Sp. z o.o.Plac Bankowy 2, 00-102 Warsaw, Poland
Email: [email protected]
Phone: +48 22 511 1900