Legal
Privacy & Cookies Policy
PrimumAI — Ireland / EU. How we handle personal data as a controller, and how we handle patient data on behalf of the clinics we process for.
Effective date 11 September 2025
- Controller
- PrimumAi Limited (CRO 777714)
- For PrimumAI’s own data
- Processor
- PrimumAi Limited
- For Clinic patient data
- Lead supervisory authority
- Data Protection Commission
- Ireland
Scope & Roles
- Processor role
- Patient data handled for Clinics. The Clinic is Controller; PrimumAI follows instructions.
- Controller role
- Our own business data (accounts, billing, service emails, product telemetry, website analytics and consents, vendor management, security logs). We do not act as Controller for patient records.
Contact Details & DPO
- harsh@primumai.eu — also for deletion requests.
- Office
- Apartment 31, Block B02, Roselawn, Knocksinna Court, Blackrock, Co. Dublin, A94 A4T8
Personal Data We Process (Controller role)
Identity and contact details; account and usage data; support tickets; billing (no card numbers stored); website and consent information. No patient records.
Our Purposes & Legal Bases
- Contract
- Provide the service, support, and billing.
- Legitimate interests
- Security, availability, and product improvement (aggregated).
- Legal obligations
- Tax and lawful disclosures.
- Consent
- Marketing communications and non-essential cookies.
Special Category Data
Not as Controller. As Processor, we handle patient health data on Clinic instructions under Article 9(2)(h).
Children
The service targets professionals. Clinics remain responsible if minors’ data is entered. The age of digital consent in Ireland is 16.
International Transfers
EEA by default. If a transfer is required: SCCs, TIAs, and supplementary measures. Regions are listed in Annex C.
Security (Summary)
We apply the Annex B TOMs: encryption, MFA, RBAC, tenant isolation, logging and monitoring, and incident response.
Retention
- Controller data
- Kept for the life of the account, then deleted or anonymised; backups purge within 30–45 days. Billing follows statutory rules.
- Processor data
- Retained only as instructed by the Clinic. Deletion requests should be sent to harsh@primumai.eu.
Your Rights (Controller data)
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Request via harsh@primumai.eu. We reply within one month (extensions possible).
How to Make a Request
Send an email to harsh@primumai.eu. We verify identity, assess scope, act, and confirm. For patient data, contact your Clinic — we assist them.
AI Transparency
AI suggestions are drafts; a clinician approves them. EU region AI services are configured not to train on Clinic data. Clinics can disable AI features.
Changes
We update this policy and notify you of material changes.
Complaints
Contact harsh@primumai.eu. You may escalate to the Data Protection Commission (dataprotection.ie). We will cooperate fully.
Addendum: Data Received from Third Parties (v1.1)
How we get personal data from other sources — Article 14 GDPR
Sometimes we receive personal data about you from other sources instead of directly from you. When this happens, we will tell you clearly and quickly about it. We do this to stay transparent and to respect your rights.
Typical sources
- Your clinic or healthcare provider (for onboarding, appointment management, and care coordination)
- Previous systems during data migration that your clinic asks us to perform
- Telephony and messaging providers (e.g. Twilio) for call and SMS metadata and consent logs
- Payment service providers (for tokenised payment confirmations and fraud prevention)
- Referral partners or booking platforms used by your clinic
- Public or professional directories (clinician details) where legally allowed
- Our security and logging systems (technical and usage metadata)
What we get
Depending on the service, this can include: name, contact details, appointment details, billing references, call and SMS metadata, consent choices, and — only when your clinic instructs us — clinical note content or audio for transcription. We do not collect more than we need for the task.
Why we get it, and our legal bases
- To provide services your clinic asked for (e.g. AI scribe, AI receptionist, booking and billing) — Contract, Art. 6(1)(b)
- To protect our platform and comply with law — Legal obligation, Art. 6(1)(c), and Legitimate interests, Art. 6(1)(f)
- For health-related processing under a clinic’s responsibility — Health care, Art. 9(2)(h)
- Marketing only with your opt-in consent — Consent, Art. 6(1)(a); you can withdraw at any time
Who we share with
We use trusted providers to run our services: AWS (EU) for hosting and email, Microsoft Azure (EU) including Azure OpenAI EU, and Twilio for calls and SMS. Any international routing is protected by EU-approved safeguards (e.g. SCCs or BCRs).
How long we keep it
We keep data only as long as needed: appointment reminders ≤12 months, support tickets ≤24 months, consent and cookie logs 13 months, security logs 12 months, and clinical content as instructed by your clinic. Backups are encrypted and time-limited.
When and how we contact you about this
If we received your data from someone else, we will provide you with this information:
- our details and contact, including the DPO
- the purposes and legal bases
- the types of data and the source
- any recipients and transfers
- retention and your rights (access, rectification, erasure, restriction, portability, objection)
- how to complain to the Data Protection Commission
We will do this within one month of getting your data, or at the time of our first communication with you, or before sharing your data with anyone else — whichever happens first.
If we cannot contact you
If contacting you is impossible or would take a disproportionate effort (for example, no contact details, or a large archival dataset), we will keep a record of why we could not contact you and how we still protect your data, as allowed by Article 14(5).
Your choices
You can ask questions or use your rights at any time by emailing harsh@primumai.eu. We answer as quickly as we can, and always within legal timelines.
Version control
| Version | Date | Reviewed by | Approved by | Change |
|---|---|---|---|---|
| 1.110 | October 2025 | Harsh Mangla (DPO) | Management | Added Article 14 section for third-party sources |
Questions about this policy?
Our DPO answers privacy enquiries directly at harsh@primumai.eu. For patient records held on behalf of a clinic, contact the clinic — we assist them with the request. The contractual terms are set out in our Terms of Service.