Privacy

Privacy Policy

Last Updated: 1 September 2026

Introduction

Synduct GmbH ("Synduct," "we," "us," "our") operates https://synduct.com and DR. INFO AI (collectively, the "Services").

This Privacy Policy governs your visit to https://synduct.com and your use of DR. INFO AI, explaining how we collect, safeguard, and disclose information that results from your use of the Services.

We use your data to provide and improve the Services. By using them, you agree to the collection and use of information in accordance with this Policy. Our Terms and Conditions ("Terms") and this Privacy Policy apply to all use of our Services.

Definitions

TermMeaning
ServiceThe websites https://synduct.com and DR. INFO AI
Personal DataData about a person who can be identified from those data
Usage DataData collected automatically (generated by use of the Services or their infrastructure, e.g., duration of a page visit)
CookiesFiles stored on your device
Data ControllerThe natural or legal person who determines the purposes and means of processing Personal Data
Data ProcessorA natural or legal person who processes data on behalf of the Data Controller (e.g., service providers)
Data SubjectAny person who is the subject of Personal Data
UserAny person using our Services; corresponds to the Data Subject

Types of Data Collected

Personal Data

We may ask you to provide personally identifiable information that can be used to contact or identify you, including but not limited to:

  • Email address
  • First and last name
  • Profession
  • Years of Experience
  • Place of Work
  • Institution
  • Specialties
  • Country
  • Cookies and Usage Data

We may use your Personal Data to contact you with newsletters, marketing or promotional materials, and other information (e.g., a wait-list for the launch of DR. INFO AI). You can opt out of any—or all—such communications by following the unsubscribe link in our emails.

Usage Data

We may collect information that your browser or app sends whenever you access the Services, such as:

  • IP address
  • Browser type and version
  • Pages of our Services visited
  • Date and time of visit
  • Time spent on pages / in app
  • Unique device identifiers
  • Other diagnostic data

When accessing the Services via a mobile device, Usage Data may additionally include:

  • Mobile-device unique ID
  • Mobile-device IP address
  • Mobile operating system
  • Type of mobile Internet browser used

Use of Data

Synduct uses collected data for, but not limited to, the following purposes:

  • Notifying you about changes to the Services
  • Providing customer support
  • Gathering analysis or valuable information to improve the Services
  • Monitoring usage of the Services
  • Detecting, preventing, and addressing technical issues
  • Fulfilling any purpose for which you provided the data
  • Carrying out obligations and enforcing rights under contracts between you and us (including billing and collection)
  • Sending notices about your account or subscription (e.g., expiration or renewal)
  • Providing news or special offers
  • Any other purpose described when you provide the information
  • Any other purpose with your consent

Retention of Data

We retain Personal Data only as long as necessary for the purposes set out in this Policy. Account data is retained for the duration of your account and deleted on account closure. Transient processing copies are deleted within 24 hours of completing the task. Backup copies are deleted through the backup rotation, at the latest after 90 days. For the Scribe and Reports features, retention periods are governed by the applicable Data Processing Agreement (see the Scribe and Clinical Documentation section below). We also retain data as needed to comply with legal obligations, resolve disputes, and enforce agreements.

Transfer of Data

Patient data processed through the Scribe and Reports features is processed exclusively within the EU/EEA (and, for speech-to-text transcription, the United Kingdom under an EU adequacy decision); it is never transferred to the United States. Limited non-clinical data (for example, website analytics and, where you consent, Meta advertising measurement) may be processed by providers established in the United States. For such transfers we rely on the EU-US Data Privacy Framework where the recipient is certified and, as a fallback, on Standard Contractual Clauses under Article 46 GDPR, together with supplementary technical and organisational measures. No transfer takes place unless these safeguards are in place.

Third-Party AI Services

For the AI search and voice-search features, DR. INFO uses third-party services to generate responses to clinical questions, to retrieve relevant medical literature, and to transcribe voice input. We use Google Gemini (via Google Cloud Vertex AI, EU region) to generate medical responses and to transcribe voice-search audio, and Tavily to retrieve relevant clinical sources from authoritative medical literature. The Scribe feature is described separately in the Scribe and Clinical Documentation section below.

For the search and voice-search features, we send only the text of your clinical question (or, for voice search, the audio recording of your spoken query) to these providers. We do not send your name, email, account identifier, device identifier, IP address, location, or any patient information. This does not apply to the Scribe feature, which processes patient data as described below.

Processing is performed on the legal basis of contractual necessity under GDPR Article 6(1)(b), in order to provide the service you request. Where data is transferred to the United States, transfers are protected by EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

By using the AI search or voice search features in DR. INFO, you provide your explicit consent under GDPR Article 9(2)(a) for the processing of your query text and voice recordings by the AI providers named above. You may withdraw your consent at any time by discontinuing use of these features.

Query data is retained only for the time needed to return a response, is not used to train AI models, and is not shared with further third parties beyond what is necessary to deliver the response.

Processing and Sharing of Queries

When using the search features, we collect the medical queries you submit. These queries are never linked to your personal details and must not include any patient-identifiable information. This restriction applies to the search features only; the Scribe and Reports features are described separately below.

We may analyse, aggregate, and anonymise search queries. Anonymised or aggregated search-query data may be shared with third parties (such as research institutions or healthcare organisations) for research or analytical purposes. Such data will never include your personal information and cannot reasonably be traced back to you. For the avoidance of doubt, consultation recordings, transcripts, notes, discharge letters and reports created through the Scribe and Reports features are never included in this, are never sold, and are never used for research; clinical content of this kind is only ever pseudonymised, not sold or repurposed.

Scribe and Reports — processing of patient data

For patient data processed through Scribe and Reports / Discharge Letter, Synduct generally acts as Processor on behalf of the healthcare provider using the service. The healthcare provider remains responsible for the applicable legal basis, patient information and management of patient rights and consent where applicable. Synduct assists the Controller in accordance with the Data Processing Agreement (DPA).

Depending on the feature used (Scribe or Reports / Discharge Letter), processing may include consultation audio, consultation transcripts, clinical notes, diagnoses, medication and treatment information, uploaded clinical documents, and draft reports, summaries and discharge letters. These data may constitute health data within Article 9 GDPR.

For Scribe, consultation audio is transmitted for speech-to-text transcription and the resulting transcript may be further processed to structure draft documentation. For Reports / Discharge Letter, submitted clinical information is processed for extraction, structuring and generation of a draft document. The precise processing profile, sub-processors and retention periods are determined by the operative DPA and its applicable Annexes.

Under the current documented model, Scribe audio is intended to be deleted within five minutes after transcription. Other transient copies and generated content are retained or deleted according to the applicable processing profile and Retention and Deletion Concept. Where patient-derived documentation is retained in the service, it remains subject to the Controller's instructions, applicable data-subject rights and the operative retention rules for as long as it remains personal data.

Identifiable or pseudonymised patient data processed through Scribe and Reports is not used by Synduct for training, fine-tuning or evaluating AI models. Scribe recordings, transcripts and chart entries derived from Scribe are excluded from any separate anonymised training-data programme under the current DPA framework.

Patients should normally exercise rights relating to patient data through the healthcare provider acting as Controller. If Synduct receives a request concerning patient data processed on behalf of a Controller, Synduct will forward the request to the relevant Controller and assist as required under the DPA.

Disclosure of Data

We may disclose Personal Data:

  • To comply with legal obligations or valid requests by public authorities
  • To contractors, service providers, and other third parties who support our business
  • To fulfill the purpose for which you provided it
  • With your consent in any other case

Security of Data

We employ robust technical and organizational measures to protect Personal Data (including special categories of data such as health data under Article 9 GDPR) against unauthorized access, disclosure, alteration, loss, or destruction, including:

  • Encryption
  • Access controls
  • Pseudonymisation and de-identification
  • Regular audits and testing
  • Secure infrastructure
  • Staff training

Despite these measures, no method of transmission over the Internet or electronic storage is 100% secure; therefore, absolute security cannot be guaranteed.

Your GDPR Rights

Our processing activities adhere to the principles of the General Data Protection Regulation (GDPR). To inquire about, access, update, or delete Personal Data we hold about you, email info@synduct.com.

Under certain circumstances, you have the right to:

  • Access, update, or delete your information
  • Rectify inaccurate or incomplete data
  • Object to processing of your Personal Data
  • Request restriction of processing
  • Receive a copy of your data in a structured, machine-readable format
  • Withdraw consent at any time where we rely on consent to process data

We may require identity verification before fulfilling such requests. You also have the right to lodge a complaint with your competent supervisory authority. Our lead supervisory authority is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA).

Service Providers

We may employ third-party companies and individuals to facilitate our Services, perform service-related tasks, or help us analyze how the Services are used. These third parties have access to Personal Data only to perform tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Our current third-party processors include:

  • Google Cloud EMEA Ltd. (cloud infrastructure, database, user authentication, and AI processing via Vertex AI)
  • Vercel Inc. (Hosting and Analytics)
  • Microsoft Corporation (Azure services)
  • Firebase (Authentication)
  • Meta Platforms Ireland Ltd. (Advertising and Conversion Measurement — joint controller under Article 26 GDPR)
  • Speechmatics Ltd. (speech-to-text transcription for the Scribe feature)

Analytics

Google Analytics

We use Google Analytics to track and report website traffic. Google may use the collected data to contextualize and personalize its own advertising network. For more details, see Google's Privacy Policy and its guidance on safeguarding data. Google Analytics runs only on our public website; it is not used within the clinical DR. INFO application or the Scribe and Reports features, and it never processes patient data.

Vercel Analytics

We use Vercel Analytics for hosting performance monitoring and aggregated usage metrics. For details on how Vercel processes this data, refer to Vercel's Privacy Policy.

Meta Pixel

We deploy the Meta Pixel (provided by Meta Platforms Ireland Ltd.) for advertising on Meta platforms, conversion attribution, and the creation of custom and lookalike audiences. The Meta Pixel loads only after you have given explicit consent to Targeting & Advertising cookies. Synduct GmbH and Meta Platforms Ireland Ltd. act as joint controllers within the meaning of Article 26 GDPR for this processing; the joint-controllership terms are set out in Meta's Controller Addendum (facebook.com/legal/controller_addendum). Data is transferred to Meta Platforms, Inc. in the United States subject to the safeguards described in the Transfer of Data section below. The Meta Pixel runs only on our public website; it is not used within the clinical DR. INFO application or the Scribe and Reports features, and it never processes patient data.

Payments

For paid products or services, we use third-party payment processors. We do not store your payment-card details; they are provided directly to the processor, whose use of your information is governed by its own Privacy Policy.

Links to Other Sites

Our Services may contain links to external sites not operated by us. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over, and assume no responsibility for, the content or practices of any third-party sites or services.

Children's Privacy

Our Services are intended for licensed healthcare professionals and are not directed to individuals under 18 years of age. We do not knowingly collect Personal Data from anyone under 18. If we become aware that such data has been collected, we will delete it promptly.

Updates to This Privacy Policy

We may update this Privacy Policy periodically. We will notify you of changes by posting the new Policy, updating the "effective date," and, where appropriate, notifying you via email or a prominent notice within the Services. Changes become effective once posted.

Contact Us

If you have any questions about this Privacy Policy, contact us at:

Data Protection Contact

For any questions, requests, or complaints relating to the processing of your Personal Data, you can contact our data-protection team at:

Email: regulatory@synduct.com

By using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

Version: 1.1
Last Review Date: 1 September 2026