Senest opdateret: oktober 2026 · Version 1.0 for Danmark (pilotdrift)
Applikationen «Medenda» («Tjenesten») stiller software til rådighed for klinikker til håndtering af aftaler, patienter og betalinger samt AI-receptionisten «Menda». Efter databeskyttelsesforordningen (EU 2016/679, «GDPR») og databeskyttelsesloven gælder:
Dataansvarlig for patienternes oplysninger er den enkelte klinik, der registrerer dem og bestemmer formålet. Databehandler er leverandøren af Tjenesten: NORTH DIGITAL LABS MONOPROSOPI I.K.E., reg.nr. 194336303000, Leoforos Kifisias 265, 145 61 Kifisia, Grækenland, e-mail: privacy@medenda.ai. Forholdet er reguleret af en Databehandleraftale (DPA), som indgås med hver klinik. For oplysninger om klinikkens egne brugere (konti) og om besøgende på hjemmesiden er leverandøren selv dataansvarlig.
| Kategori | Oplysninger | Formål |
|---|---|---|
| Brugere af Tjenesten (behandlere, sekretærer) | E-mail, navn, krypteret adgangskode, tilknyttet klinik, login-tidspunkter | Oprettelse af konto, sikker login, drift af Tjenesten |
| Patienter (registreres af klinikken) | Navn, telefon, e-mail, fødselsdato, klinikkens noter, aftaler, betalinger, transskriptioner og resuméer af opkald til Menda | Håndtering af klinikkens aftaler og patientkartotek, udelukkende på klinikkens vegne |
| Personer der ringer til Menda | Telefonnummer (nummervisning), det der siges i samtalen (som tekst), navn og ønsket tid, hvis det oplyses | Besvarelse af opkaldet, booking af aftaler, beskeder til klinikken |
| Tekniske oplysninger | IP-adresse, browsertype (logges af hostinginfrastrukturen) | Sikkerhed, forebyggelse af misbrug, teknisk drift |
Patienters helbredsoplysninger er en «særlig kategori» af oplysninger (GDPR artikel 9). Retsgrundlaget for behandlingen tilhører klinikken som dataansvarlig (typisk levering af sundhedsydelser, GDPR artikel 9, stk. 2, litra h). Tjenesten behandler dem udelukkende efter klinikkens instruks.
Når en patient ringer til klinikkens Menda-nummer, besvares opkaldet af et automatisk system. Talen omsættes løbende til tekst, så Menda kan forstå og svare; til det formål sendes lyden i realtid til vores leverandør af taleteknologi (se afsnit 5). Der gemmes ingen lydoptagelse af samtalen. Efter opkaldet gemmes en skriftlig transskription og et kort resumé i klinikkens system, så klinikken kan se, hvad der er aftalt, og følge op på beskeder. Transskriptionen og resuméet er klinikkens data og slettes sammen med klinikkens øvrige data. Klinikken er ansvarlig for at informere sine patienter om, at telefonen besvares af en AI-receptionist, og om behandlingen af deres oplysninger.
Databasen hostes af Supabase Inc. på Amazon Web Services-infrastruktur i Frankfurt, Tyskland (eu-central-1). Oplysningerne forbliver i EU. Der anvendes kryptering under overførsel (TLS) og ved lagring (encryption at rest).
| Leverandør | Rolle | Dataplacering |
|---|---|---|
| Supabase Inc. | Database og brugerlogin | EU, Frankfurt (AWS eu-central-1) |
| Vercel Inc. | Hosting af appens hjemmeside (statisk indhold, gemmer ikke patientdata) | Globalt CDN |
| ElevenLabs Inc. | AI-receptionisten Menda: talegenkendelse, talesyntese og samtalestyring. ElevenLabs anvender sprogmodeller fra OpenAI til at forstå og formulere svar. | USA (med EU-standardkontraktbestemmelser, SCC) |
| Zadarma Ltd. | Telefoni (Mendas danske telefonnumre) og afsendelse af SMS-påmindelser | EU |
| Viva.com (Viva Payments) | Behandling af abonnementsbetalinger | EU |
| Elorus (Bekraft I.K.E.) | Udstedelse af fakturaer | EU (Grækenland) |
| Google LLC (Google Calendar API) | Valgfri tovejs-synkronisering af aftaler med klinikkens Google Kalender | USA / Googles globale infrastruktur (SCC) |
| Google Fonts / jsDelivr | Skrifttype og teknisk bibliotek (hentes når siden åbnes; den besøgendes IP kan blive overført) | Globalt CDN |
Oplysningerne gemmes i EU. Undtagelsesvis overføres samtaledata i realtid til ElevenLabs Inc. (USA) for at drive AI-receptionisten, og til Google LLC (USA), hvis klinikken selv vælger at forbinde Google Kalender. Disse overførsler er omfattet af EU-Kommissionens standardkontraktbestemmelser (SCC) efter GDPR kapitel V. En fuldstændig og opdateret liste findes i bilaget til Databehandleraftalen.
Kun klinikkens autoriserede brugere med personlig konto og adgangskode. Adskillelsen af data mellem klinikker håndhæves på databaseniveau (Row Level Security). Tilføjelse af en ny bruger kræver en invitationskode, som klinikken styrer, og klinikken kan når som helst fjerne en bruger eller udstede en ny kode. Leverandørens tekniske adgang sker kun i forbindelse med support eller vedligeholdelse.
Hvis klinikkens administrator vælger det, forbindes Tjenesten med klinikkens Google-konto for tovejs-synkronisering af aftaler med Google Kalender. Tjenesten får i så fald adgang til (a) Google-kontoens e-mailadresse, så det kan vises, hvilken konto der er forbundet, og (b) kalenderbegivenheder, udelukkende for at oprette, opdatere og slette de begivenheder, der svarer til klinikkens aftaler, og for at læse, hvornår behandleren er optaget, så der ikke tilbydes optagne tider til patienter.
Oplysninger modtaget via Google API'er sælges ikke, videregives ikke til tredjeparter, bruges ikke til reklame og bruges ikke til at udvikle eller træne AI-modeller. Adgangstokens gemmes sikkert i Tjenestens database og slettes, når klinikken afbryder Google Kalender i appens Indstillinger. Adgangen kan også tilbagekaldes fra Google-kontoens sikkerhedsindstillinger (myaccount.google.com/permissions). Brugen af oplysninger fra Google API'er overholder Google API Services User Data Policy, herunder kravene om begrænset brug (Limited Use).
Hvis klinikken har slået SMS-påmindelser til, sendes der én SMS til patienten dagen før aftalen med klinikkens navn, dato og tidspunkt. Til det formål overføres patientens telefonnummer og beskedteksten til vores SMS-leverandør. Der sendes ikke markedsføring pr. SMS.
Tjenesten bruger udelukkende teknisk nødvendig lokal lagring (local storage) på din enhed: din sessionsnøgle, så du forbliver logget ind, dit sprogvalg og dit valg vedrørende cookie-meddelelsen. Der bruges ingen reklame- eller trackingcookies og ingen analyseværktøjer fra tredjeparter. Teknisk nødvendige elementer kræver ikke samtykke efter cookiebekendtgørelsen og ePrivacy-direktivet.
Så længe klinikkens konto er aktiv. Ved opsigelse eller ophør slettes klinikkens data endeligt inden for 30 dage (eller udleveres først til klinikken i elektronisk form, hvis det ønskes). Klinikken er fortsat ansvarlig for sine egne journalførings- og opbevaringspligter efter dansk sundhedslovgivning; Tjenesten er ikke et journalsystem.
Enhver fysisk person har rettighederne i GDPR artikel 15-22: indsigt, berigtigelse, sletning («retten til at blive glemt»), begrænsning, dataportabilitet og indsigelse. Er du patient, skal du rette din henvendelse til din klinik (den dataansvarlige); Tjenesten hjælper klinikken teknisk med at opfylde den. Er du bruger af Tjenesten, kan du skrive til e-mailadressen i afsnit 1. Du har også ret til at klage til Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk, eller til tilsynsmyndigheden i det EU-land, hvor du bor.
Tekniske og organisatoriske foranstaltninger omfatter blandt andet: TLS-kryptering ved al overførsel, kryptering ved lagring, adskillelse af klinikkernes data på databaseniveau (RLS), personlige konti med adgangskode, mulighed for øjeblikkelig tilbagekaldelse af adgang, regelmæssige sikkerhedskopier. Ved brud på persondatasikkerheden underretter leverandøren de berørte klinikker uden ugrundet ophold, så fristerne i GDPR artikel 33 kan overholdes (anmeldelse til tilsynsmyndigheden inden 72 timer, hvor det kræves).
Væsentlige ændringer meddeles i appen, inden de træder i kraft.
Denne tekst gælder for pilotdriften i Danmark og er under juridisk gennemgang. Den danske version er en oversættelse; i tilfælde af uoverensstemmelse har den engelske version forrang. Se også Brugsvilkårene.
NORTH DIGITAL LABS MONOPROSOPI I.K.E. (enkeltmands-IKE efter græsk ret) · Reg.nr. (G.E.MI.) 194336303000 · EU-momsnr. EL803311290 · Leoforos Kifisias 265, 145 61 Kifisia, Grækenland · privacy@medenda.ai
Last updated: October 2026 · Version 1.0 for Denmark (pilot operation)
The «Medenda» application (the «Service») provides clinics with software for managing appointments, patients and payments, plus the «Menda» AI receptionist. Under the General Data Protection Regulation (EU 2016/679, «GDPR») and the Danish Data Protection Act:
The data controller for patient data is the individual clinic that enters it and determines the purpose. The processor is the provider of the Service: NORTH DIGITAL LABS MONOPROSOPI I.K.E., reg. no. 194336303000, Leoforos Kifisias 265, 145 61 Kifisia, Greece, e-mail: privacy@medenda.ai. This relationship is governed by a Data Processing Agreement (DPA) concluded with each clinic. For data about the clinic's own users (accounts) and website visitors, the provider is itself the controller.
| Category | Data | Purpose |
|---|---|---|
| Users of the Service (practitioners, reception staff) | E-mail, name, encrypted password, clinic they belong to, login times | Account creation, secure login, operation of the Service |
| Patients (entered by the clinic) | Name, phone, e-mail, date of birth, clinic notes, appointments, payments, transcripts and summaries of calls to Menda | Managing the clinic's appointments and patient records, solely on behalf of the clinic |
| People calling Menda | Phone number (caller ID), what is said during the call (as text), name and requested time if provided | Answering the call, booking appointments, messages for the clinic |
| Technical data | IP address, browser type (logged by the hosting infrastructure) | Security, abuse prevention, technical operation |
Patients' health data is a «special category» of data (GDPR Article 9). The legal basis for processing it belongs to the clinic as controller (typically provision of health care, GDPR Article 9(2)(h)). The Service processes it strictly on the clinic's instructions.
When a patient calls the clinic's Menda number, the call is answered by an automated system. Speech is continuously converted to text so that Menda can understand and reply; for this purpose the audio is streamed in real time to our speech-technology provider (see section 5). No audio recording of the conversation is stored. After the call, a written transcript and a short summary are stored in the clinic's system so the clinic can see what was agreed and follow up on messages. The transcript and summary are the clinic's data and are deleted together with the clinic's other data. The clinic is responsible for informing its patients that the phone is answered by an AI receptionist and about the processing of their data.
The database is hosted by Supabase Inc. on Amazon Web Services infrastructure in Frankfurt, Germany (eu-central-1). Data remains within the EU. Encryption is applied in transit (TLS) and at rest.
| Provider | Role | Data location |
|---|---|---|
| Supabase Inc. | Database and user authentication | EU, Frankfurt (AWS eu-central-1) |
| Vercel Inc. | Hosting of the app's website (static content, stores no patient data) | Global CDN |
| ElevenLabs Inc. | The Menda AI receptionist: speech recognition, speech synthesis and conversation handling. ElevenLabs uses OpenAI language models to understand and formulate replies. | USA (with EU Standard Contractual Clauses, SCCs) |
| Zadarma Ltd. | Telephony (Menda's Danish phone numbers) and sending of SMS reminders | EU |
| Viva.com (Viva Payments) | Processing of subscription payments | EU |
| Elorus (Bekraft I.K.E.) | Issuing of invoices | EU (Greece) |
| Google LLC (Google Calendar API) | Optional two-way sync of appointments with the clinic's Google Calendar | USA / Google's global infrastructure (SCCs) |
| Google Fonts / jsDelivr | Font and technical library (loaded when the page opens; the visitor's IP may be transmitted) | Global CDN |
Data is stored in the EU. By exception, conversation data is transmitted in real time to ElevenLabs Inc. (USA) to operate the AI receptionist, and to Google LLC (USA) if the clinic chooses to connect Google Calendar. These transfers are covered by the European Commission's Standard Contractual Clauses (SCCs) under Chapter V of the GDPR. A complete and up-to-date list is kept in the annex to the Data Processing Agreement.
Only the clinic's authorised users, each with a personal account and password. Separation of data between clinics is enforced at database level (Row Level Security). Adding a new user requires an invitation code controlled by the clinic, which can remove a user or issue a new code at any time. Technical access by the provider occurs only for support or maintenance.
If the clinic's administrator chooses so, the Service connects to the clinic's Google account for two-way synchronisation of appointments with Google Calendar. The Service then gains access to (a) the Google account's e-mail address, to show which account is connected, and (b) calendar events, solely to create, update and delete the events corresponding to the clinic's appointments and to read when the practitioner is busy so that occupied slots are not offered to patients.
Information received via Google APIs is not sold, not shared with third parties, not used for advertising and not used to develop or train AI models. Access tokens are stored securely in the Service's database and deleted when the clinic disconnects Google Calendar in the app's Settings. Access can also be revoked from the Google account's security settings (myaccount.google.com/permissions). Use of information from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
If the clinic has enabled SMS reminders, one SMS is sent to the patient the day before the appointment with the clinic's name, date and time. For this purpose the patient's phone number and the message text are transmitted to our SMS provider. No marketing is sent by SMS.
The Service uses only technically necessary local storage on your device: your session key so you stay logged in, your language choice and your choice regarding the cookie notice. No advertising or tracking cookies and no third-party analytics tools are used. Technically necessary elements do not require consent under the Danish cookie rules and the ePrivacy Directive.
For as long as the clinic's account is active. On cancellation or termination, the clinic's data is permanently deleted within 30 days (or first handed over to the clinic in electronic form, if requested). The clinic remains responsible for its own record-keeping and retention obligations under Danish health legislation; the Service is not a medical record system.
Every natural person has the rights in GDPR Articles 15-22: access, rectification, erasure («right to be forgotten»), restriction, data portability and objection. If you are a patient, address your request to your clinic (the controller); the Service supports the clinic technically in fulfilling it. If you are a user of the Service, write to the e-mail address in section 1. You also have the right to lodge a complaint with Datatilsynet (the Danish Data Protection Agency), Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk, or with the supervisory authority of the EU country where you live.
Technical and organisational measures include: TLS encryption for all transfers, encryption at rest, separation of clinics' data at database level (RLS), personal accounts with passwords, immediate revocation of access, regular backups. In the event of a personal data breach, the provider notifies the affected clinics without undue delay so the deadlines of GDPR Article 33 can be met (notification to the supervisory authority within 72 hours where required).
Material changes are announced in the app before they take effect.
This text covers the pilot operation in Denmark and is under legal review. The Danish version is a translation; in case of discrepancy the English version prevails. See also the Terms of Service.
NORTH DIGITAL LABS MONOPROSOPI I.K.E. (single-member private company under Greek law) · Reg. no. (G.E.MI.) 194336303000 · EU VAT no. EL803311290 · Leoforos Kifisias 265, 145 61 Kifisia, Greece · privacy@medenda.ai