WellNest Scribe is a clinical AI documentation platform operated for use in
Caribbean healthcare facilities. This policy explains what data we collect, why
we collect it, and how we protect it.
2. Data We Collect
Account data
Name, email address, and password (hashed - we never store plaintext passwords).
Specialty, facility name, and clinical role.
Login timestamps and IP addresses (retained for 90 days for security audit purposes).
Patient session data
Audio recordings of consultations (encrypted at rest; auto-deleted after 30 days).
Patient name, identifier, and gender as entered by the clinician.
Transcripts and AI-generated SOAP notes (encrypted at rest using AES-256 Fernet).
Session metadata: date, duration, note format, and clinical flags.
Usage data
Feature usage logs for system performance and quality improvement.
Error logs (anonymised where possible).
3. How We Use Your Data
To provide the Service - transcribing audio and generating clinical notes.
For security - detecting unauthorised access, brute-force attempts, and data breaches.
For compliance - audit logs required under Caribbean data protection legislation.
To improve the Service - aggregate, anonymised usage analytics only. We do not use
identifiable patient data to train AI models.
4. Data Storage & Security
All data is hosted on secure cloud infrastructure, with AES-256
encryption at rest on all storage and database services.
Patient-identifiable fields (names, transcripts, note content) are additionally
encrypted at the application layer using Fernet symmetric encryption
before being written to the database. The encryption key is held in a
dedicated key management service, separate from the database itself.
All connections are encrypted in transit using TLS 1.2 or higher.
The application enforces HTTPS, HSTS, and CSRF protection.
Login attempts are rate-limited; repeated failures trigger an account lockout and
an alert to the facility administrator.
5. Data Sharing
We do not sell, rent, or share patient data with third parties for
marketing purposes. Data is shared only with:
Secure AI service providers, which may be located outside Jamaica
(including in the United States), for the sole purpose of generating transcriptions
and notes. These providers are bound to process the data only for that purpose and
not to use it to train their models.
Your organisation’s administrators who have legitimate access
under the role-based access control system.
Law enforcement or regulators only when compelled by applicable law,
and only to the extent required.
6. Data Retention
Audio recordings - deleted automatically 30 days after creation (configurable by administrator).
Session notes and transcripts - retained until the account administrator or the doctor deletes them.
Login audit logs - retained for 90 days.
Deleted sessions - permanently purged within 30 days of deletion.
7. Your Rights
Under applicable Caribbean data protection legislation, you and your patients have
the right to:
Access personal data held about you.
Request correction of inaccurate data.
Request deletion (“right to erasure”) subject to legal retention requirements.
Object to specific processing activities.
Lodge a complaint with the relevant national data protection authority.
We use a single session cookie (HttpOnly, Secure in production) to maintain your
login state. We do not use third-party tracking cookies or analytics cookies.
9. Children
The Service is not intended for use by individuals under 18. Patient data relating
to minors may only be processed by clinicians with appropriate guardian consent under
their applicable professional and legal obligations.
10. Changes to This Policy
We will notify account administrators of material changes by email at least 30 days
before they take effect. Continued use after that date constitutes acceptance.