← Tilbage til appen← Back to the app

Privatlivspolitik

Senest opdateret: oktober 2026 · Version 1.0 for Danmark (pilotdrift)

Kort fortalt: hver kliniks data tilhører klinikken, gemmes krypteret på servere i EU, sælges ikke og bruges aldrig til reklame. Kun klinikkens autoriserede brugere har adgang. Opkald til Menda gemmes ikke som lyd, kun som tekst.

1. Hvem vi er, og hvilke roller vi har

Applikationen «Medenda» («Tjenesten») stiller software til rådighed for klinikker til håndtering af aftaler, patienter og betalinger samt AI-receptionisten «Menda». Efter databeskyttelsesforordningen (EU 2016/679, «GDPR») og databeskyttelsesloven gælder:

Dataansvarlig for patienternes oplysninger er den enkelte klinik, der registrerer dem og bestemmer formålet. Databehandler er leverandøren af Tjenesten: NORTH DIGITAL LABS MONOPROSOPI I.K.E., reg.nr. 194336303000, Leoforos Kifisias 265, 145 61 Kifisia, Grækenland, e-mail: privacy@medenda.ai. Forholdet er reguleret af en Databehandleraftale (DPA), som indgås med hver klinik. For oplysninger om klinikkens egne brugere (konti) og om besøgende på hjemmesiden er leverandøren selv dataansvarlig.

2. Hvilke oplysninger vi behandler

KategoriOplysningerFormål
Brugere af Tjenesten (behandlere, sekretærer)E-mail, navn, krypteret adgangskode, tilknyttet klinik, login-tidspunkterOprettelse af konto, sikker login, drift af Tjenesten
Patienter (registreres af klinikken)Navn, telefon, e-mail, fødselsdato, klinikkens noter, aftaler, betalinger, transskriptioner og resuméer af opkald til MendaHåndtering af klinikkens aftaler og patientkartotek, udelukkende på klinikkens vegne
Personer der ringer til MendaTelefonnummer (nummervisning), det der siges i samtalen (som tekst), navn og ønsket tid, hvis det oplysesBesvarelse af opkaldet, booking af aftaler, beskeder til klinikken
Tekniske oplysningerIP-adresse, browsertype (logges af hostinginfrastrukturen)Sikkerhed, forebyggelse af misbrug, teknisk drift

Patienters helbredsoplysninger er en «særlig kategori» af oplysninger (GDPR artikel 9). Retsgrundlaget for behandlingen tilhører klinikken som dataansvarlig (typisk levering af sundhedsydelser, GDPR artikel 9, stk. 2, litra h). Tjenesten behandler dem udelukkende efter klinikkens instruks.

3. AI-receptionisten Menda og telefonopkald

Når en patient ringer til klinikkens Menda-nummer, besvares opkaldet af et automatisk system. Talen omsættes løbende til tekst, så Menda kan forstå og svare; til det formål sendes lyden i realtid til vores leverandør af taleteknologi (se afsnit 5). Der gemmes ingen lydoptagelse af samtalen. Efter opkaldet gemmes en skriftlig transskription og et kort resumé i klinikkens system, så klinikken kan se, hvad der er aftalt, og følge op på beskeder. Transskriptionen og resuméet er klinikkens data og slettes sammen med klinikkens øvrige data. Klinikken er ansvarlig for at informere sine patienter om, at telefonen besvares af en AI-receptionist, og om behandlingen af deres oplysninger.

4. Hvor oplysningerne gemmes

Databasen hostes af Supabase Inc. på Amazon Web Services-infrastruktur i Frankfurt, Tyskland (eu-central-1). Oplysningerne forbliver i EU. Der anvendes kryptering under overførsel (TLS) og ved lagring (encryption at rest).

5. Underdatabehandlere

LeverandørRolleDataplacering
Supabase Inc.Database og brugerloginEU, Frankfurt (AWS eu-central-1)
Vercel Inc.Hosting af appens hjemmeside (statisk indhold, gemmer ikke patientdata)Globalt CDN
ElevenLabs Inc.AI-receptionisten Menda: talegenkendelse, talesyntese og samtalestyring. ElevenLabs anvender sprogmodeller fra OpenAI til at forstå og formulere svar.USA (med EU-standardkontraktbestemmelser, SCC)
Zadarma Ltd.Telefoni (Mendas danske telefonnumre) og afsendelse af SMS-påmindelserEU
Viva.com (Viva Payments)Behandling af abonnementsbetalingerEU
Elorus (Bekraft I.K.E.)Udstedelse af fakturaerEU (Grækenland)
Google LLC (Google Calendar API)Valgfri tovejs-synkronisering af aftaler med klinikkens Google KalenderUSA / Googles globale infrastruktur (SCC)
Google Fonts / jsDelivrSkrifttype og teknisk bibliotek (hentes når siden åbnes; den besøgendes IP kan blive overført)Globalt CDN

Oplysningerne gemmes i EU. Undtagelsesvis overføres samtaledata i realtid til ElevenLabs Inc. (USA) for at drive AI-receptionisten, og til Google LLC (USA), hvis klinikken selv vælger at forbinde Google Kalender. Disse overførsler er omfattet af EU-Kommissionens standardkontraktbestemmelser (SCC) efter GDPR kapitel V. En fuldstændig og opdateret liste findes i bilaget til Databehandleraftalen.

6. Hvem har adgang

Kun klinikkens autoriserede brugere med personlig konto og adgangskode. Adskillelsen af data mellem klinikker håndhæves på databaseniveau (Row Level Security). Tilføjelse af en ny bruger kræver en invitationskode, som klinikken styrer, og klinikken kan når som helst fjerne en bruger eller udstede en ny kode. Leverandørens tekniske adgang sker kun i forbindelse med support eller vedligeholdelse.

7. Google Kalender-synkronisering (Google-brugerdata)

Hvis klinikkens administrator vælger det, forbindes Tjenesten med klinikkens Google-konto for tovejs-synkronisering af aftaler med Google Kalender. Tjenesten får i så fald adgang til (a) Google-kontoens e-mailadresse, så det kan vises, hvilken konto der er forbundet, og (b) kalenderbegivenheder, udelukkende for at oprette, opdatere og slette de begivenheder, der svarer til klinikkens aftaler, og for at læse, hvornår behandleren er optaget, så der ikke tilbydes optagne tider til patienter.

Oplysninger modtaget via Google API'er sælges ikke, videregives ikke til tredjeparter, bruges ikke til reklame og bruges ikke til at udvikle eller træne AI-modeller. Adgangstokens gemmes sikkert i Tjenestens database og slettes, når klinikken afbryder Google Kalender i appens Indstillinger. Adgangen kan også tilbagekaldes fra Google-kontoens sikkerhedsindstillinger (myaccount.google.com/permissions). Brugen af oplysninger fra Google API'er overholder Google API Services User Data Policy, herunder kravene om begrænset brug (Limited Use).

8. SMS-påmindelser

Hvis klinikken har slået SMS-påmindelser til, sendes der én SMS til patienten dagen før aftalen med klinikkens navn, dato og tidspunkt. Til det formål overføres patientens telefonnummer og beskedteksten til vores SMS-leverandør. Der sendes ikke markedsføring pr. SMS.

9. Cookies og lokal lagring

Tjenesten bruger udelukkende teknisk nødvendig lokal lagring (local storage) på din enhed: din sessionsnøgle, så du forbliver logget ind, dit sprogvalg og dit valg vedrørende cookie-meddelelsen. Der bruges ingen reklame- eller trackingcookies og ingen analyseværktøjer fra tredjeparter. Teknisk nødvendige elementer kræver ikke samtykke efter cookiebekendtgørelsen og ePrivacy-direktivet.

10. Hvor længe oplysningerne gemmes

Så længe klinikkens konto er aktiv. Ved opsigelse eller ophør slettes klinikkens data endeligt inden for 30 dage (eller udleveres først til klinikken i elektronisk form, hvis det ønskes). Klinikken er fortsat ansvarlig for sine egne journalførings- og opbevaringspligter efter dansk sundhedslovgivning; Tjenesten er ikke et journalsystem.

11. Dine rettigheder

Enhver fysisk person har rettighederne i GDPR artikel 15-22: indsigt, berigtigelse, sletning («retten til at blive glemt»), begrænsning, dataportabilitet og indsigelse. Er du patient, skal du rette din henvendelse til din klinik (den dataansvarlige); Tjenesten hjælper klinikken teknisk med at opfylde den. Er du bruger af Tjenesten, kan du skrive til e-mailadressen i afsnit 1. Du har også ret til at klage til Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk, eller til tilsynsmyndigheden i det EU-land, hvor du bor.

12. Sikkerhed

Tekniske og organisatoriske foranstaltninger omfatter blandt andet: TLS-kryptering ved al overførsel, kryptering ved lagring, adskillelse af klinikkernes data på databaseniveau (RLS), personlige konti med adgangskode, mulighed for øjeblikkelig tilbagekaldelse af adgang, regelmæssige sikkerhedskopier. Ved brud på persondatasikkerheden underretter leverandøren de berørte klinikker uden ugrundet ophold, så fristerne i GDPR artikel 33 kan overholdes (anmeldelse til tilsynsmyndigheden inden 72 timer, hvor det kræves).

13. Ændringer af denne politik

Væsentlige ændringer meddeles i appen, inden de træder i kraft.

Denne tekst gælder for pilotdriften i Danmark og er under juridisk gennemgang. Den danske version er en oversættelse; i tilfælde af uoverensstemmelse har den engelske version forrang. Se også Brugsvilkårene.

NORTH DIGITAL LABS MONOPROSOPI I.K.E. (enkeltmands-IKE efter græsk ret) · Reg.nr. (G.E.MI.) 194336303000 · EU-momsnr. EL803311290 · Leoforos Kifisias 265, 145 61 Kifisia, Grækenland · privacy@medenda.ai

Privacy Policy

Last updated: October 2026 · Version 1.0 for Denmark (pilot operation)

In short: each clinic's data belongs to the clinic, is stored encrypted on servers in the EU, is never sold and never used for advertising. Only the clinic's authorised users have access. Calls to Menda are not stored as audio, only as text.

1. Who we are and our roles

The «Medenda» application (the «Service») provides clinics with software for managing appointments, patients and payments, plus the «Menda» AI receptionist. Under the General Data Protection Regulation (EU 2016/679, «GDPR») and the Danish Data Protection Act:

The data controller for patient data is the individual clinic that enters it and determines the purpose. The processor is the provider of the Service: NORTH DIGITAL LABS MONOPROSOPI I.K.E., reg. no. 194336303000, Leoforos Kifisias 265, 145 61 Kifisia, Greece, e-mail: privacy@medenda.ai. This relationship is governed by a Data Processing Agreement (DPA) concluded with each clinic. For data about the clinic's own users (accounts) and website visitors, the provider is itself the controller.

2. What data we process

CategoryDataPurpose
Users of the Service (practitioners, reception staff)E-mail, name, encrypted password, clinic they belong to, login timesAccount creation, secure login, operation of the Service
Patients (entered by the clinic)Name, phone, e-mail, date of birth, clinic notes, appointments, payments, transcripts and summaries of calls to MendaManaging the clinic's appointments and patient records, solely on behalf of the clinic
People calling MendaPhone number (caller ID), what is said during the call (as text), name and requested time if providedAnswering the call, booking appointments, messages for the clinic
Technical dataIP address, browser type (logged by the hosting infrastructure)Security, abuse prevention, technical operation

Patients' health data is a «special category» of data (GDPR Article 9). The legal basis for processing it belongs to the clinic as controller (typically provision of health care, GDPR Article 9(2)(h)). The Service processes it strictly on the clinic's instructions.

3. The Menda AI receptionist and phone calls

When a patient calls the clinic's Menda number, the call is answered by an automated system. Speech is continuously converted to text so that Menda can understand and reply; for this purpose the audio is streamed in real time to our speech-technology provider (see section 5). No audio recording of the conversation is stored. After the call, a written transcript and a short summary are stored in the clinic's system so the clinic can see what was agreed and follow up on messages. The transcript and summary are the clinic's data and are deleted together with the clinic's other data. The clinic is responsible for informing its patients that the phone is answered by an AI receptionist and about the processing of their data.

4. Where data is stored

The database is hosted by Supabase Inc. on Amazon Web Services infrastructure in Frankfurt, Germany (eu-central-1). Data remains within the EU. Encryption is applied in transit (TLS) and at rest.

5. Sub-processors

ProviderRoleData location
Supabase Inc.Database and user authenticationEU, Frankfurt (AWS eu-central-1)
Vercel Inc.Hosting of the app's website (static content, stores no patient data)Global CDN
ElevenLabs Inc.The Menda AI receptionist: speech recognition, speech synthesis and conversation handling. ElevenLabs uses OpenAI language models to understand and formulate replies.USA (with EU Standard Contractual Clauses, SCCs)
Zadarma Ltd.Telephony (Menda's Danish phone numbers) and sending of SMS remindersEU
Viva.com (Viva Payments)Processing of subscription paymentsEU
Elorus (Bekraft I.K.E.)Issuing of invoicesEU (Greece)
Google LLC (Google Calendar API)Optional two-way sync of appointments with the clinic's Google CalendarUSA / Google's global infrastructure (SCCs)
Google Fonts / jsDelivrFont and technical library (loaded when the page opens; the visitor's IP may be transmitted)Global CDN

Data is stored in the EU. By exception, conversation data is transmitted in real time to ElevenLabs Inc. (USA) to operate the AI receptionist, and to Google LLC (USA) if the clinic chooses to connect Google Calendar. These transfers are covered by the European Commission's Standard Contractual Clauses (SCCs) under Chapter V of the GDPR. A complete and up-to-date list is kept in the annex to the Data Processing Agreement.

6. Who has access

Only the clinic's authorised users, each with a personal account and password. Separation of data between clinics is enforced at database level (Row Level Security). Adding a new user requires an invitation code controlled by the clinic, which can remove a user or issue a new code at any time. Technical access by the provider occurs only for support or maintenance.

7. Google Calendar sync (Google user data)

If the clinic's administrator chooses so, the Service connects to the clinic's Google account for two-way synchronisation of appointments with Google Calendar. The Service then gains access to (a) the Google account's e-mail address, to show which account is connected, and (b) calendar events, solely to create, update and delete the events corresponding to the clinic's appointments and to read when the practitioner is busy so that occupied slots are not offered to patients.

Information received via Google APIs is not sold, not shared with third parties, not used for advertising and not used to develop or train AI models. Access tokens are stored securely in the Service's database and deleted when the clinic disconnects Google Calendar in the app's Settings. Access can also be revoked from the Google account's security settings (myaccount.google.com/permissions). Use of information from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

8. SMS reminders

If the clinic has enabled SMS reminders, one SMS is sent to the patient the day before the appointment with the clinic's name, date and time. For this purpose the patient's phone number and the message text are transmitted to our SMS provider. No marketing is sent by SMS.

9. Cookies and local storage

The Service uses only technically necessary local storage on your device: your session key so you stay logged in, your language choice and your choice regarding the cookie notice. No advertising or tracking cookies and no third-party analytics tools are used. Technically necessary elements do not require consent under the Danish cookie rules and the ePrivacy Directive.

10. How long data is kept

For as long as the clinic's account is active. On cancellation or termination, the clinic's data is permanently deleted within 30 days (or first handed over to the clinic in electronic form, if requested). The clinic remains responsible for its own record-keeping and retention obligations under Danish health legislation; the Service is not a medical record system.

11. Your rights

Every natural person has the rights in GDPR Articles 15-22: access, rectification, erasure («right to be forgotten»), restriction, data portability and objection. If you are a patient, address your request to your clinic (the controller); the Service supports the clinic technically in fulfilling it. If you are a user of the Service, write to the e-mail address in section 1. You also have the right to lodge a complaint with Datatilsynet (the Danish Data Protection Agency), Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk, or with the supervisory authority of the EU country where you live.

12. Security

Technical and organisational measures include: TLS encryption for all transfers, encryption at rest, separation of clinics' data at database level (RLS), personal accounts with passwords, immediate revocation of access, regular backups. In the event of a personal data breach, the provider notifies the affected clinics without undue delay so the deadlines of GDPR Article 33 can be met (notification to the supervisory authority within 72 hours where required).

13. Changes to this policy

Material changes are announced in the app before they take effect.

This text covers the pilot operation in Denmark and is under legal review. The Danish version is a translation; in case of discrepancy the English version prevails. See also the Terms of Service.

NORTH DIGITAL LABS MONOPROSOPI I.K.E. (single-member private company under Greek law) · Reg. no. (G.E.MI.) 194336303000 · EU VAT no. EL803311290 · Leoforos Kifisias 265, 145 61 Kifisia, Greece · privacy@medenda.ai