Last Updated: October 1st 2026
At EE Dojo, Inc. (operating as ScribeMD.ai), we are committed to protecting your privacy and ensuring the security of personal data. This Privacy Policy explains how we collect, use, disclose and safeguard personal data when you use ScribeMD.ai, an AI medical scribe that allows clinicians to record or dictate patient consultations and that transcribes them and generates clinical notes, letters, billing codes and related documentation (the "Service"). This policy applies to individuals in the European Union and the European Economic Area (EEA).
ScribeMD.ai is provided by EE Dojo, Inc., a California-based corporation. Our Service is offered to healthcare professionals and healthcare organisations (our "Customers"), not directly to patients.
EE Dojo, Inc. (D/B/A ScribeMD.ai)
10000 Washington Blvd, Suite 607
Culver City, CA 90232, USA
This policy is designed to comply with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), together with the applicable national data protection and health-information laws of the EU and EEA Member States. Our use of cookies and similar technologies follows the rules implementing the ePrivacy Directive (2002/58/EC); see our Cookie Policy. We also take into account the transparency obligations of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) as they apply to AI systems that interact with people or generate content.
Where ScribeMD.ai acts as controller, we process personal data for the following purposes and on the following legal bases under Article 6 GDPR:
Where ScribeMD.ai acts as processor, the purposes and legal bases for processing patient data are determined by the Customer as controller.
Health data is a special category of personal data under Article 9 GDPR. Clinical data processed through the Service is processed on behalf of clinicians for the purposes of medical diagnosis, the provision of health care or treatment and the management of health care systems and services, in reliance on Article 9(2)(h) GDPR, and in accordance with Article 9(3) GDPR and applicable Member State law, under the responsibility of professionals who are subject to an obligation of professional secrecy. Clinicians remain responsible for determining the applicable legal basis, for informing patients and, where required by local law, for obtaining patient consent.
We do not sell patient data and we do not use identifiable patient data to train AI models. We may create aggregated and anonymised statistics from which no individual, Customer or case can be identified.
We do not sell personal data. We may share personal data in the following circumstances:
By default, the Service is hosted in the United States, and personal data may be transferred to and processed outside the EU/EEA. Where this occurs, we rely on an adequacy decision of the European Commission or on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). Where a recipient in the United States is certified under the EU–US Data Privacy Framework, the corresponding adequacy decision may also apply to transfers to that recipient. We carry out transfer impact assessments and apply supplementary measures, including encryption in transit and at rest, to protect transferred data.
We offer local data hosting options so that Customer Data, including patient health data, can be stored in the Customer's own region. Where a local hosting option is agreed in writing with a Customer, that Customer's data is stored in the agreed region. For any specific question about hosting, data location or these documents, please contact contact@scribemd.ai.
We implement appropriate technical and organisational measures in line with Article 32 GDPR, including encryption in transit and at rest, and access restricted to authorised personnel on a need-to-know basis. However, no method of electronic transmission or storage is completely secure.
Patient and clinical data is retained in accordance with the Customer's configuration and documented instructions. On termination of the Service, we delete or return such data in accordance with the Customer's instructions, unless retention is required by EU or Member State law. Account and billing data is retained for as long as necessary to provide the Service and to meet our legal, accounting and tax obligations, after which it is securely deleted or anonymised.
Subject to the conditions and exceptions in the GDPR, you have the following rights:
To exercise your rights regarding data for which ScribeMD.ai is the controller, contact us at contact@scribemd.ai. We will respond within one month, which may be extended where permitted by the GDPR. We may need to verify your identity before acting on a request.
If you are a patient, your clinician or clinic is the controller of your clinical data, and you should normally contact them first. If you contact us directly, we will refer your request to the relevant Customer and assist them in responding.
The Service uses artificial intelligence to transcribe consultations and to generate draft clinical documentation. All AI-generated output is a draft that must be reviewed, edited where necessary and approved by the clinician, who remains responsible for the clinical record. ScribeMD.ai does not make decisions based solely on automated processing that produce legal or similarly significant effects concerning patients or users. The Service is not intended to provide diagnosis or treatment decisions.
Where we act as processor, we will notify the affected Customer without undue delay after becoming aware of a personal data breach, and provide the information reasonably available to us, so that the Customer can meet its obligation to notify the competent supervisory authority within 72 hours under Article 33 GDPR and, where required, to inform affected individuals. Where we act as controller, we will notify the competent supervisory authority and affected individuals as required by Articles 33 and 34 GDPR.
The Service is intended for healthcare professionals and organisations and is not directed at children. Clinicians may process data relating to child patients as controllers, in accordance with applicable law. We do not knowingly collect personal data directly from children for our own purposes.
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last Updated" date. Where changes are material, we will give Customers reasonable advance notice by email or through the Service.
If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA Member State of your habitual residence, your place of work or the place of the alleged infringement. A list of the national supervisory authorities is published by the European Data Protection Board: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en. We would, however, appreciate the opportunity to address your concerns first, so please feel free to contact us.
For any questions about this Privacy Policy, to exercise your rights, or for questions about hosting and data location, please contact us at:
EE Dojo, Inc. (D/B/A ScribeMD.ai)
10000 Washington Blvd, Suite 607
Culver City, CA 90232, USA
Email: contact@scribemd.ai
Last Updated: October 1st 2026