🇺🇸 United States 🇨🇦 Canada 🇮🇱 Israel 🇿🇦 South Africa 🇧🇷 Brazil 🇬🇧 United Kingdom 🇪🇺 European Union 🇦🇺 Australia 🇳🇿 New Zealand

🇳🇿 Privacy Policy for EE Dojo, Inc. (D/B/A ScribeMD.ai)

Last Updated: October 1st 2026

At EE Dojo, Inc. (operating as ScribeMD.ai), we are committed to protecting personal information and health information and to keeping it secure. ScribeMD.ai is an AI medical scribe: healthcare professionals record or dictate patient consultations, and the Service transcribes them and generates draft clinical notes, letters, billing codes and other documentation. This Privacy Policy explains how we collect, use, disclose and safeguard personal information when our customers in New Zealand, their staff and their patients interact with ScribeMD.ai (the "Service"). It is written for New Zealand and reflects the Privacy Act 2020 and the Health Information Privacy Code 2020.

1. Who We Are

ScribeMD.ai is provided by EE Dojo, Inc. (D/B/A ScribeMD.ai), a California-based corporation. Our customers are healthcare professionals and healthcare organisations, such as general practices, specialists and clinics (each a "Customer" or "clinician").

EE Dojo, Inc. (D/B/A ScribeMD.ai)

10000 Washington Blvd, Suite 607

Culver City, CA 90232, USA

2. Applicable Legislation

This policy is designed to comply with:

3. Our Role

3.1 Patient and clinical information

The clinician or clinic using the Service is the "health agency" responsible for patient health information under the HIPC. When we process recordings, transcripts, clinical notes and other patient information, we do so as the Customer's service provider (in the language of data protection, a processor), acting only on the Customer's documented instructions. Under section 11 of the Privacy Act 2020, where we hold information on a Customer's behalf solely for safe custody or processing, and do not use or disclose it for our own purposes, that information is treated as being held by the Customer, not by us. The Customer remains responsible for complying with the HIPC, including its obligations under the Health (Retention of Health Information) Regulations 1996.

3.2 Account, billing and website information

For information about our Customers and their users (for example, account details, billing information, support requests and website usage), ScribeMD.ai is the agency responsible for that information under the Privacy Act 2020 (in data protection terms, the controller).

4. Information We Collect

5. How We Collect Information

We collect information directly from you when you create an account, use the Service, contact us or pay for a subscription; automatically through your use of the Service and our website; and, for patient information, from the clinician who records or enters it into the Service. Patient information is collected by the clinician, who is responsible for making patients aware of the collection as required by rule 3 of the HIPC. Where we collect personal information about you indirectly for our own purposes, we will take reasonable steps to make you aware of it as required by IPP 3A, unless an exception applies.

6. Purposes for Using Information

We collect and use personal information only for lawful purposes connected with our functions and activities (IPP 1), namely:

Patient information is used only to provide the Service to the Customer in accordance with the Customer's instructions.

7. Health Information

Health information is particularly sensitive. We process patient health information solely to deliver transcription and clinical documentation services to the Customer. We do not sell patient information, and we do not use identifiable patient information to train AI models. We may create aggregated and anonymised or de-identified statistics from which no individual, practice or case can be identified, directly or indirectly. We do not use or disclose patient health information for any other purpose except as instructed by the Customer or as required by law.

8. Sharing and Sub-processors

We do not sell personal information. We share information only as follows:

9. Cross-Border Disclosure

By default, the Service is hosted in the United States, and information may be processed in the United States unless a local hosting option has been agreed (see section 10). Where our sub-processors hold patient information on our behalf solely for storage or processing, they act as agents under section 11 of the Privacy Act 2020 and the information remains treated as held by the Customer. Where personal information is disclosed to a foreign person or entity in circumstances covered by IPP 12 (and rule 12 of the HIPC), we disclose it only where the recipient is required to protect it in a way that, overall, provides comparable safeguards to those in the Privacy Act 2020, including through contractual safeguards.

10. Local Data Hosting Options

We offer local data hosting options so that Customer Data, including patient health information, can be stored in the Customer's own region. Where a local hosting option is agreed in writing with a Customer, that Customer's data is stored in the agreed region. Local hosting is available on request and is not the default configuration. If you have any question about hosting, where data is stored, or this policy, please contact contact@scribemd.ai.

11. Storage and Security

In line with IPP 5 and rule 5 of the HIPC, we take reasonable security safeguards to protect personal information against loss, unauthorised access, use, modification or disclosure, and other misuse. Data is encrypted in transit and at rest, and access is restricted to authorised personnel who need it to provide and support the Service. No method of electronic transmission or storage is completely secure, but we review and improve our safeguards regularly.

12. Retention

We keep personal information only for as long as required for the purposes for which it may lawfully be used (IPP 9 and rule 9 of the HIPC). Patient information is retained in accordance with the Customer's configuration of the Service and the Customer's instructions. On termination of a Customer's account, Customer Data is returned or deleted in accordance with our agreement with the Customer, except where we are required by law to retain it. Clinicians remain responsible for retaining health records as required by the Health (Retention of Health Information) Regulations 1996 and other applicable law. Account and billing information is kept for as long as the account is active and afterwards as needed for legal, tax and accounting purposes.

13. Your Rights

Under the Privacy Act 2020 and the HIPC, you have the right to:

Patients: because your clinician is the health agency responsible for your health information, please make access or correction requests to your clinician or practice first. We will assist the clinician in responding to your request. If you contact us directly, we will refer your request to the relevant clinician where appropriate.

Customers and users: to exercise your rights regarding account information, contact contact@scribemd.ai. We may need to verify your identity before acting on a request, and we will respond within the timeframes required by the Privacy Act 2020.

14. Automated Processing

The Service uses AI to produce draft transcripts and documentation. All AI output is a draft that the clinician must review, edit where necessary and approve before relying on it. The Service is not intended to provide diagnosis or treatment decisions, and we do not make decisions about individuals based solely on automated processing that have legal or similarly significant effects.

15. Privacy Breaches

If we become aware of a privacy breach affecting patient information that we hold on a Customer's behalf, we will notify the affected Customer as soon as practicable and provide the information and assistance reasonably required so that the Customer can assess whether it is a notifiable privacy breach under Part 6 of the Privacy Act 2020 and, if so, notify the Privacy Commissioner and affected individuals. Where a notifiable privacy breach involves information for which ScribeMD.ai is responsible, we will notify the Privacy Commissioner and affected individuals as required by the Act.

16. Children

The Service is intended for healthcare professionals and is not directed at children. Clinicians may use the Service in consultations involving children, in which case the clinician is responsible for handling that health information in accordance with the HIPC.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last Updated" date, and we will notify Customers of material changes in advance by email or through the Service.

18. Complaints and the Privacy Commissioner

If you have a concern about how we handle personal information, please contact us first at contact@scribemd.ai so we can try to resolve it. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner: www.privacy.org.nz.

19. Contact Us

For any question about this Privacy Policy, to exercise your rights, or about hosting and data location, please contact:

EE Dojo, Inc. (D/B/A ScribeMD.ai)

10000 Washington Blvd, Suite 607

Culver City, CA 90232, USA

Email: contact@scribemd.ai

Last Updated: October 1st 2026