Vocali
Back to home Get in touch
Legal

Privacy and data processing notice

Last updated 31 August 2026
Contents
Introduction 1. Definitions 2. What data we process 3. Audio recording and temporary storage 4. Guided onboarding 5. Transcription 6. Masking the transcription 7. Document generation using AI 8. Retention periods 9. Metadata we collect 10. Access, security and confidentiality 11. Sub-processors and data transfers 12. Informing the patient and consent 13. Data subject rights 14. Cookies 15. Contact details 16. Changes to this Notice

Introduction

This privacy and data processing notice (the Notice) explains how and why UAB Vocali processes personal data when the Vocali solution is used. It applies:

  • when a Vocali account is used to produce medical documentation;
  • when you contact us in other ways — support, training, sales or other Vocali-related matters.

Vocali is bought in one of two ways, and this determines who is responsible for the data:

  • Institution model. A healthcare institution buys Vocali for its staff. The institution is the Controller and Vocali is the Processor. Retention periods are set by the institution's administrator for all of its users.
  • Individual practice model. A clinician subscribes to Vocali directly. The clinician (or their practice) is the Controller, and they set the retention periods themselves in their own account settings.
If you do not agree with this Notice or with the practices described in it, please do not use Vocali.

01 Definitions

Personal data — any information relating to a natural person.

Data subject — the natural person whose personal data is processed. With Vocali this is primarily the patient, and also the User.

Processor — UAB Vocali, legal entity code 307111508, registered office at Šiaulių g. 10-56, LT-01134, Vilnius, Lithuania.

Controller — the healthcare institution that buys and uses Vocali to produce its medical documentation, or the self-subscribing clinician (individual practice model).

User — the natural person who has access to the Vocali platform and uses it within the rights and responsibilities granted to them.

Vocali — an AI-based solution that gives healthcare professionals the means to complete administrative tasks quickly, accurately and efficiently, using an audio recording of the patient visit, its transcription and structured processing of the information. Vocali produces and fills in a medical document automatically, reducing the administrative burden so more attention goes to the patient.

Services — any interaction with the Company through Vocali or related activity.

Sub-processor — a service provider we engage to deliver the Services, processing data on our instructions under a data processing agreement. The list is set out in the Data processing annex.

GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.

STT — automatic speech recognition (Speech-to-Text).

LLM — large language model.

02 What data we process

Vocali is built on Privacy by Design & Default principles: we collect only what the Services cannot work without. The categories of data we process are:

  • Patient visit data. The audio recording of the clinician-patient conversation, its transcription and the content of the generated medical document. This is special category (health) data and is subject to the masking and retention periods described in this Notice.
  • Guided onboarding data. The audio recording of the User reading a test scenario aloud, its transcription, the generated test form and a technical speech-recognition quality score. Guided onboarding is not intended for recording a patient consultation or any patient data.
  • User account data. First and last name, work email address, position or specialty, account role, sign-in time.
  • Technical metadata. Technical measurements about a given patient visit, never linked to the patient's personal data (see section 9).
  • Billing data. In the individual practice model, subscription and invoice data. We neither receive nor store payment card details — those are handled by the payment service provider.
  • Security records. Sign-in attempts, IP address and activity logs needed to detect and investigate unauthorised access.
  • Technical error records. When an error occurs in the platform, a technical report is sent to an error monitoring service in the European Union: the description of the error, browser and device details, IP address and the sequence of user actions. Some sessions are also recorded technically so it is clear which actions produced the error; in such recordings all text content is masked and images and audio are not recorded.

03 Audio recording and temporary storage

Vocali works by recording the clinician-patient conversation during the visit. Recording is started in the browser by the User; an audio file recorded earlier can also be uploaded.

Processing runs while the recording is being made: the audio is transmitted over an encrypted channel to a processing environment in the European Union and transcribed before the visit has ended, rather than afterwards. The recording is also held in the browser for the duration of the session so the User can listen back to it; that copy is stored nowhere else and disappears when the page is closed or reloaded, or when the User clears the recording.

In the processing environment the recording is held only while processing runs: once the document has been produced, both the recording and all its intermediate parts are irreversibly deleted. Storage is configured so that a deleted file cannot be restored. If the User discards the recording in the platform, the audio already transmitted is deleted from storage without delay.

Interrupted sessions

If recording or processing is interrupted by circumstances outside Vocali's control — a power cut, loss of internet connectivity, the browser or device shutting down, or the page being closed or reloaded mid-recording — some intermediate files (audio parts already transmitted, unused intermediate transcriptions) can be left behind in the processing environment, because nothing remains to finish and clear them.

An automatic clean-up therefore runs: unused intermediate processing files are cleared from the processing environment at least once every 24 hours, whether or not the session was completed. Such fragments never enter the medical document history and never enter backups.

04 Guided onboarding

Guided onboarding is an optional test feature that helps the User learn how to start a recording, produce a document and use Vocali's main functions. It provides a prepared test scenario containing no patient or other person's data. Before recording begins, the User is clearly told not to record a real patient consultation or provide any patient data.

When the User reads the test scenario aloud, the audio is transcribed, the transcription is masked and a test form is generated from it. This data is used only to provide guided onboarding, assess microphone and speech-recognition quality and diagnose technical problems. It is not used to train or improve artificial intelligence models.

The onboarding audio recording is held in the European Union for no longer than 3 days and is deleted automatically once that period ends. The unmasked transcription is used only during processing and is not retained. The masked transcription is kept until the User's account is deleted, unless the User or the Controller requests its earlier deletion. The test form generated during onboarding is subject to the Controller's selected retention period for generated documents, described in section 8.

05 Transcription

The recording is converted to text automatically using the Google Cloud speech recognition service. The service is configured so that processing takes place in the European Union.

Under the data processing agreement concluded with the provider, the data is used solely to deliver the service and is not used to train or improve artificial intelligence models.

At this stage the transcription is not yet de-identified, so it is held only as long as it is needed to produce the document, and is deleted together with the recording. For interrupted sessions, the clean-up described in section 3 applies.

06 Masking the transcription

Before the transcription is passed on for further processing, an automatic filtering and masking step runs in our environment. The system is configured to detect and mask these categories of personal data:

  • names and surnames;
  • national identification numbers;
  • identity document numbers (identity card, passport);
  • places and addresses;
  • telephone numbers;
  • email addresses.

Detected data is replaced with neutral placeholders (for example [PERSON_1], [PERSONAL_CODE_2]), and the same value is replaced with the same placeholder throughout the transcription — so the text stays comprehensible while the identity does not survive. Only the de-identified version of the transcription reaches further processing.

Masking is automatic and therefore, like any automatic recognition, not absolute — particularly for data written unusually or spoken imprecisely during the conversation. We apply further safeguards: the language model is separately instructed not to include any identifying data in the final document, and the generated document is always reviewed by the User before it is used.

07 Document generation using AI

The de-identified transcription is passed to the Google Cloud generative AI service, where LLM-based text processing runs. The service is configured so that processing takes place in the European Union.

Under the data processing agreement concluded with the provider, the data is neither retained on the provider's side nor used to train or improve models.

Once the transcription has been processed, the final medical document content is produced and delivered to the User's browser for review, correction and confirmation. How long that document is kept is decided by the Controller — see section 8.

Where an institution has enabled additional features, the following related data is also processed:

  • Source links. So the User can check which part of the conversation a given field was filled in from, the corresponding de-identified transcription excerpts are stored. They are never kept longer than the de-identified transcription itself.
  • Documentation rules. Recurring patterns in the User's own documentation habits (for example how they phrase a conclusion) are derived automatically from the edits they make, so the next document is closer to their style. Only the rules and their rationale are stored, never patient data; the User can review, disable and delete them in the platform.
  • Integrations with the institution's information system. A document confirmed by the User can be transferred to the institution's information system. In that case the external record identifier is stored so it is known which record the document belongs to.

08 Retention periods

The Controller selects the retention periods for the generated patient-visit document and the de-identified patient-visit transcription. Separate periods shown in the table below apply to other categories of data, including guided onboarding data. Three options are available for the patient-visit document and de-identified transcription:

  1. Delete after review. Data is kept only for as long as the User is working with it. A document being drafted is stored so that it can be edited, supplemented by voice, switched to another template and compared across versions — including after returning to an unfinished visit. Once the User has reviewed and confirmed the document, it and the de-identified transcription are both removed immediately and no history is kept; with an integration, only once the document has been transferred successfully to the User's information system. Data from an unfinished visit is removed in the first daily cleanup after 24 hours have passed since the visit record was created.
  2. Keep for a set period. Data is kept for the chosen number of days, and once that period ends it is removed automatically and irreversibly.
  3. Keep indefinitely. Data is kept until the User or the Controller deletes it.

Who sets this choice:

  • Institution model — the institution's administrator, in one setting for the whole institution. The User can see the period in their account but cannot change it.
  • Individual practice model — the clinician, in their own account settings. The choice can be changed at any time, including after the subscription has ended, so the owner of the data can remove it whenever they wish.

Whatever the choice, the User can delete any or all stored documents manually in the platform at any time.

DataRetention period
Audio recording in the browserUntil the User clears it, or the page is closed or reloaded
Audio recording during processingDeleted once processing completes; unused fragments cleared at least once every 24 hours
De-identified transcriptionThe Controller's choice (three options above)
Generated medical documentThe Controller's choice (three options above)
Source excerptsNever longer than the de-identified transcription
Unapplied dictated changesUntil applied or discarded, and in any case no longer than 24 hours
Technical metadataFor the term of the agreement; irreversibly anonymised within 30 days of its end
Onboarding audio recordingNo longer than 3 days; may be deleted earlier at the User's or Controller's request
Masked onboarding transcriptionUntil the User's account is deleted, unless deleted earlier at the User's or Controller's request
Test form generated during onboardingThe Controller's selected retention period for generated documents
User account dataFor as long as the account exists
Billing dataFor the retention period prescribed by accounting law
Security recordsFor as long as needed to detect and investigate unauthorised access
Backups. After data is deleted in the platform, a copy may remain for up to 7 days in the automated database backups that exist for service continuity. After 7 days the backups are removed automatically and irreversibly. This means a deletion request is carried out in the platform immediately, and in backups no later than within 7 days.

09 Metadata we collect

The metadata in this section is technical — it is not and cannot be linked to a patient's personal data. It is collected solely to deliver the Services, keep them running, account for volume, and analyse and improve them. Its retention is tied to the term of the service agreement: once that ends, all metadata relating to it is irreversibly anonymised within 30 (thirty) days, removing any link to an individual User.

The metadata collected is:

  • Visit recording date and time — when the recording was made.
  • User identifier — linked to the system user, but not to patient personal data.
  • Recording duration and fragment count — how long the recording was and how many parts it was split into for processing.
  • Processing durations — the time taken for audio processing, STT and LLM analysis.
  • Transcription word and character counts.
  • Generated document word and character counts, and the number of tokens processed by the language model.
  • Models used — version identifiers of the speech recognition and language models, needed for quality monitoring.
  • Detected languages — which languages the conversation took place in.
  • Microphone name — the device name, needed to diagnose audio quality problems.
  • User rating and feedback — numeric (1–5) and written feedback about the generated document, used to improve the service.
  • External record identifier — only where an integration with the institution's information system is in use.

10 Access, security and confidentiality

Strict access control, confidentiality and infrastructure protection principles apply across the Vocali platform. All technical and organisational measures are grounded in data protection law, including the GDPR, and follow good information security practice.

Access control

  • Access to AI tools, storage, databases, servers and other system resources is limited to pre-authorised Processor engineers and administrators, signing in with individual credentials.
  • Two-factor authentication (2FA) applies — both to internal access and to User sign-in to the platform.
  • Strong, periodically rotated passwords are used.
  • Access rights are managed on the principle of least privilege.
  • All sign-ins and actions are recorded in audit logs, enabling audits, incident analysis and attribution.

Infrastructure protection

  • All of the Processor's infrastructure — servers, databases, temporary file storage — is hosted only within the European Union.
  • All transfer of data between the User's browser, the Processor's environment and Sub-processors uses the secure TLS protocol.
  • Data is encrypted at rest using AES-256.

Backups

To ensure service continuity and data availability in the event of an incident, automated database backups are created. They are held for 7 days within the European Union, then deleted automatically and irreversibly. Audio recordings never enter backups. Generated documents and de-identified transcriptions do enter backups for as long as they are retained under section 8.

Incident management

The Controller is informed of any personal data breach without delay, and no later than 24 hours from the moment the breach is identified. In the event of a breach, the Processor takes steps to mitigate the harm, provides the necessary information and cooperates so that the duty to notify the State Data Protection Inspectorate and/or the data subjects is properly discharged. Data subjects (patients) are informed through the Controller, no later than within 72 hours, where the breach may affect them.

11 Sub-processors and data transfers

We engage a limited number of service providers to deliver the Services. A data processing agreement is in place with each of them, providing that the data:

  • is used only to deliver the Services and only on our instructions;
  • is not used to train artificial intelligence models or for any other secondary purpose;
  • is protected by the agreed technical and organisational security measures;
  • is processed in accordance with the GDPR, and any sub-contractors the provider engages are bound by the same obligations.

The categories of sub-processor in use are: the core infrastructure provider (servers and databases), the artificial intelligence provider (speech recognition and text processing), the transactional email provider, the error monitoring provider and the payment service provider.

The specific sub-processors, the functions they perform and the places of processing are set out in the Data processing annex. We notify the Controller in advance of any intended change of sub-processor, and the Controller has the right to object to a new sub-processor on reasonable grounds.

Transfers outside the EEA

Patient visit data — the audio recording, the transcription and the content of the generated document — is processed only within the European Union or the European Economic Area.

Some ancillary service providers (payments, transactional email) belong to international groups, so in individual cases — for example during technical support — a transfer outside the EEA is possible. Where that happens, the safeguards in Chapter V of the GDPR apply: standard contractual clauses approved by the European Commission, or an adequacy decision. These providers have no access to patient visit data.

12 Informing the patient and consent

Recording takes place directly during the clinician-patient consultation, so the Controller must ensure the patient is properly informed about the use of Vocali, how it works, its purposes and the data retention terms. The Controller also determines the legal basis for the processing.

The Controller must ensure the patient gives informed consent to the use of Vocali, and that the consent is clear, freely given and unambiguous. Consent may be recorded in one of the following ways:

  1. in writing, by attaching a consent form to the medical records;
  2. by digital marking in ESIS (where work is done without physical outpatient cards).

A clinician subscribing under the individual practice model discharges this duty themselves — they are the Controller.

The patient has the right to withdraw consent at any time by contacting the Controller.

13 Data subject rights

Under the GDPR, a data subject has the right to:

  • be informed about the processing of their data and to access it;
  • have inaccurate data corrected;
  • have data erased (the "right to be forgotten");
  • restrict the processing;
  • object to the processing;
  • have the data ported to another controller, where technically feasible and legally applicable;
  • lodge a complaint with the State Data Protection Inspectorate.

How to exercise these rights. The patient contacts the Controller — the healthcare institution, or the clinician whose visit Vocali was used in — because it is the Controller that determines what data is processed and for how long. Vocali, as Processor, has no legal basis to answer a patient's request on its own, but assists the Controller in fulfilling it without delay.

For their own account data, a User may contact us directly using the details in section 15.

14 Cookies

The Vocali platform uses only those cookies without which it would not work or would be less secure. The website additionally uses analytics cookies, which are set only if you agree. This is described in full in the Cookie policy.

15 Contact details

For further information about data security or data subject rights, please contact the responsible person:

Email: hello@vocali.lt

Phone: +370 689 30490

Address: UAB Vocali, Šiaulių g. 10-56, LT-01134, Vilnius, Lithuania

16 Changes to this Notice

The Processor reserves the right to update or amend this Notice at any time, including provisions relating to the security, functionality or content protection of Vocali. The current version is always available on this website, and the document's date is shown at the top of it.

The Processor undertakes to notify the Controller of material changes that may affect the use of Vocali in advance, by email or through the platform's notification tools, at least 5 (five) calendar days before they take effect.

Privacy policyTerms of useCookiesData processing annex
Vocali

Let clinicians focus on what matters most.

Product
How it worksFeaturesWho it's forSecurity
Company
AboutTeamContactEU funding
Legal
Privacy policyTerms of useCookiesData processing annex
© 2026 Vocali. All rights reserved. UAB Vocali