Privacy Policy

Privacy Policy for Stenoly

Last updated · Last updated: 06.06.2026
01

Introduction

Welcome to Stenoly! (hereinafter «Stenoly», «we» or «us»). Stenoly uses advanced artificial intelligence (AI) to transcribe speech, enabling doctors and other professional groups to quickly record essential information and save time in their daily work.

We are dedicated to protecting your privacy and processing personal data in a secure and lawful manner. This privacy policy explains how we collect, use, and protect your personal data when you use our services.

02

Data Controller

The responsibility for processing personal data when using Stenoly.no is regulated by the General Data Protection Regulation (GDPR) and the Personal Data Act. Stenoly AS is the data controller for personal data processed through our services.

Stenoly is not the data controller or data processor for any patient health information that is processed in connection with the medical professional's use of Stenoly.no. This responsibility rests with the individual doctor or professional.

Stenoly AS
Hoffsveien 4, 0275 Oslo
03

What Personal Data We Collect

We collect the following types of personal data:

  • Customer information: Including name, email address, phone number.
  • Audio data: Audio data collected via your microphone or computer.
  • Technical information: IP address, device type, browser, operating system.
  • Communication data: Email correspondence, support inquiries.
04

Purpose of Processing

We process personal data for the following purposes:

  • Provide and improve our services: To deliver and improve Stenoly.
  • Customer service: To respond to inquiries and provide support.
  • Security: To detect and prevent security threats.
  • Legal obligations: To comply with applicable laws and regulations.
06

Sharing of Personal Data

Third Parties

We do not share your personal data with third parties, unless:

  • To fulfill a contract: When necessary to deliver our services.
  • With your consent: When you have given us permission.
  • Legal requirements: When we are required to share information in accordance with law.

Subprocessors

We use the sub-processors listed below. All sub-processors that handle personal or clinical data process it within the EU/EEA under signed data processing agreements.

Infrastructure & hosting

NeonEU · Frankfurt

Database hosting.

Accounts, consultations, notes, billing.

VercelEU · Stockholm

Application hosting and file uploads.

Website traffic; uploaded documents.

AI processing of clinical data

Google Cloud (Vertex AI)EU (multi-region)

AI note generation.

Consultation transcripts and notes.

Microsoft AzureEU · Sweden

AI dictation and note processing.

Clinical text.

SpeechmaticsEU/EEA

Speech-to-text transcription.

Consultation audio, transcribed and not stored.

Mistral AIEU · France

Document text extraction.

Uploaded documents.

Authentication

SignicatEU/EEA

Authentication (BankID, Buypass, email).

Identity and login verification.

EHR integration

PridokNorway

Delivery of finished notes to the EHR.

Notes sent to the EHR.

Business & billing

HubSpotEU · Ireland

Customer relationship management.

Account contact details. No clinical data.

StripeEU / global

Subscription billing.

Billing details. No clinical data.

Google WorkspaceEU/EEA

Business email.

Email correspondence.

Customer support

ChatwootEU (self-hosted)

Customer support chat.

Support messages and contact details.

Website analytics

These run on our marketing website only and never receive patient or clinical data.

Google Analytics & Tag ManagerWebsite traffic analytics and tag management.
Meta PixelMarketing campaign measurement.

All sub-processors that handle personal or clinical data process it within the EU/EEA under signed data processing agreements.

07

Storage of Personal Data

We store personal data for as long as necessary for the purposes for which they were collected, or to comply with legal obligations. When the data is no longer necessary, it will be deleted or anonymized.

08

Your Rights

Overview of Rights

You have the right to:

  • Access: To obtain access to your personal data.
  • Rectification: To request correction of inaccurate data.
  • Erasure: To request deletion of your data.
  • Restriction: To request restriction of processing.
  • Data portability: To receive your data in a structured format.
  • Object: To object to processing when based on GDPR Article 6 (1)(f).
  • Consent: You can withdraw consent to processing of personal data that you have given to us.

Exercising Your Rights

To exercise your rights, contact us at erling@stenoly.ai.

09

Information Security

We have implemented necessary security measures to ensure that your personal data is processed in a secure manner that safeguards the confidentiality, integrity, and availability of the data. The security measures shall also protect the data against unauthorized or unlawful processing, and reduce the risk of loss, accidental alteration, unauthorized disclosure or access.

10

Changes to the Privacy Policy

We may update this privacy policy at any time to reflect changes in our privacy practices. We encourage you to regularly review the policy to stay informed about how we collect, use, and protect your information. Significant changes will be communicated via our services or directly to you.

11

Data Protection Officer

Stenoly is committed to protecting the privacy of our users and has therefore appointed a data protection officer. The data protection officer is responsible for ensuring that all processing of personal data occurs in accordance with applicable privacy legislation, including GDPR.

Contact Information

Data Protection Officer
Erling Løken Andersen
Legal Director
Hoffsveien 4, 0275 Oslo