Last Updated: October 1st 2026
At EE Dojo, Inc. (operating as ScribeMD.ai), we are committed to protecting your privacy and the confidentiality of the clinical information entrusted to us. ScribeMD.ai is an AI medical scribe: healthcare professionals record or dictate patient consultations, and the Service transcribes them and generates draft clinical notes, letters, coding suggestions and related documents. This Privacy Policy explains how we collect, use, disclose and safeguard personal data when you use the ScribeMD.ai service (the "Service") or visit our website from the United Kingdom.
EE Dojo, Inc. is a California-based corporation. The Service is offered to healthcare professionals and organisations ("Customers"); it is not offered directly to patients.
This policy is designed to comply with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 ("DPA 2018") and the Privacy and Electronic Communications Regulations 2003 ("PECR"), each as amended from time to time. Clinical information is also protected by the common-law duty of confidentiality, which our Customers owe to their patients and which we respect when processing that information on their behalf.
The organisation responsible for the Service is:
EE Dojo, Inc. (D/B/A ScribeMD.ai)
10000 Washington Blvd, Suite 607
Culver City, CA 90232, USA
Our role under the UK GDPR depends on the type of personal data:
We collect information directly from you when you register, use the Service or contact us; automatically through your use of the Service and our website (including through cookies); and, on behalf of our Customers, through the recording, dictation or entry of consultation content by the clinician.
Where we act as controller, we use personal data for the following purposes and on the following lawful bases under Article 6 UK GDPR:
Where we act as processor, we process patient and clinical data solely to provide the Service to the Customer, in accordance with the Customer's documented instructions. The Customer is responsible for identifying its own lawful basis.
Data concerning health is special category data under Article 9 UK GDPR. When Customers use the Service, they act as controllers and will typically rely on Article 9(2)(h) UK GDPR (provision of health or social care), together with the condition in Schedule 1, Part 1, paragraph 2 of the DPA 2018 (health or social care purposes). Customers remain responsible for meeting their obligations under the common-law duty of confidentiality and for informing patients about the use of the Service, including obtaining consent where their professional or local requirements call for it. Customers in the NHS or otherwise providing NHS-funded care may be subject to additional information governance requirements (for example, the Data Security and Protection Toolkit), which remain the Customer's responsibility.
We process health data only to deliver the Service. We do not sell patient data and we do not use identifiable patient data to train AI models. We may create aggregated and anonymised statistics from which no individual can be identified, and use them to operate and improve the Service.
We do not sell personal data. We share it only as follows:
By default, the Service is hosted in the United States, so personal data may be transferred outside the UK. Where we transfer personal data from the UK, we rely on UK adequacy regulations where they apply (for example, the UK Extension to the EU-US Data Privacy Framework, known as the "UK-US data bridge", only where the recipient is certified under it), or otherwise on appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. You may request further information about these safeguards by contacting us.
We offer local data hosting options so that Customer Data, including patient health data, can be stored in the Customer's own region. Where a local hosting option is agreed in writing with a Customer, that Customer's data is stored in the agreed region. Local hosting is not the default and must be agreed in writing.
For any specific question about hosting, data location or these documents, please contact contact@scribemd.ai.
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, and access restricted to authorised personnel on a need-to-know basis. No method of transmission or storage is completely secure, but we work continuously to protect the information entrusted to us.
Patient and clinical data is retained in accordance with the Customer's configuration of the Service and its documented instructions. On termination of the Customer's agreement, we delete or return that data at the Customer's choice, unless retention is required by law. Account and billing data is kept for as long as the account is active and afterwards for as long as necessary to meet legal, accounting and tax requirements or to establish, exercise or defend legal claims.
Under the UK GDPR, you have the following rights, subject to certain conditions and exemptions:
How to exercise your rights: Customers and users may contact us at contact@scribemd.ai. We will respond within one month, which may be extended by up to two further months for complex requests, as permitted by law. If you are a patient, please contact your clinician or healthcare provider first, as they are the controller of your clinical information. If we receive a request from a patient directly, we will refer it to the relevant Customer and assist them in responding.
The Service uses artificial intelligence to produce draft documentation. All AI-generated output is intended to be reviewed, edited and approved by a qualified clinician before use. The Service does not make solely automated decisions that produce legal or similarly significant effects on individuals, and it is not intended to provide diagnosis or treatment decisions.
If we become aware of a personal data breach affecting Customer Data, we will notify the affected Customer without undue delay and provide the information reasonably available to us, so that the Customer can meet its obligation to notify the Information Commissioner's Office within 72 hours where required, and to inform affected individuals where necessary. Where we are the controller, we will notify the ICO and affected individuals as required by law.
The Service is intended for healthcare professionals and is not directed at children. Customers may process information about patients who are children as part of their clinical care; in that case, the Customer as controller is responsible for meeting the applicable legal requirements.
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the "Last Updated" date. Where changes are material, we will notify Customers in advance by email or through the Service.
We encourage you to contact us first so that we can try to resolve your concern. You also have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Website: https://ico.org.uk
If you have any questions about this Privacy Policy, wish to exercise your rights, or have questions about hosting or data location, please contact us at:
EE Dojo, Inc. (D/B/A ScribeMD.ai)
10000 Washington Blvd, Suite 607
Culver City, CA 90232, USA
Email: contact@scribemd.ai
Last Updated: October 1st 2026