Privacy notice
This notice describes how MediVox AS processes personal information on the website, in customer relationships, and when delivering MediVox V4.
Last updated: August 15, 2026
1. Who is responsible for the information?
MediVox AS is the data controller for information about website visitors, account users, contacts, and other business relationships when we determine the purpose of processing.
For patient information processed in MediVox V4, the healthcare provider is normally the data controller. MediVox normally acts as a data processor under documented instructions in the data processing agreement.
2. Information we may process
- Account and identity information associated with BankID or BuyPass, user settings, and necessary activity logs.
- Audio, transcripts, journal notes, and other documents the user asks the service to process or generate.
- Contact and business information for support, agreements, billing, and partnerships.
- Technical website data. Analytics information is processed only when you consent to analytics cookies.
3. Purpose and legal basis
We process information to deliver and secure the service, administer accounts and subscriptions, support customers, meet legal obligations, and improve the website.
Depending on the situation, processing is based on a contract, legal obligation, legitimate interest, or consent. Patient information is processed on behalf of the healthcare provider under the data processing agreement; the provider is responsible for its own legal basis.
4. Retention and deletion
Audio and temporary processing data in MediVox are retained for up to 24 hours. Retention of generated text follows the selected service, user actions, and the agreement with the organization.
Account, contract, and accounting information is retained as needed for the customer relationship and legal obligations. Other information is deleted or anonymized when its purpose is fulfilled.
5. Processors and transfers
We use suppliers for cloud infrastructure, login, payment, communications, and consent-based website analytics. They are bound by agreements and may process information only for agreed purposes.
Storage regions, subprocessors, and any transfer mechanisms for patient information are governed by the data processing agreement. When information is transferred outside the EEA, we use a valid transfer mechanism and appropriate safeguards.
7. Security
We use technical and organizational measures including encrypted transmission and storage, access control, logging, limited retention, and security follow-up. No solution can guarantee completely risk-free processing.
8. Your rights
When the conditions are met, you may request access, rectification, erasure, restriction, data portability, or object to processing. You may withdraw consent at any time.
For patient information, you should normally contact the healthcare provider acting as data controller. For information controlled by MediVox, contact post@medivox.ai.
9. Complaints and changes
You may complain to the Norwegian Data Protection Authority if you believe processing violates data protection law. We may update this notice when the service or law changes; the date above identifies the latest version.
Contact details
MediVox AS · Org. no. 933 607 526
Langesgate 8, 3210 Sandefjord, Norway