Skip to main content

Clinicians: Help us shape the future of healthcare. Take the survey

Heidi AI
Log inGet Heidi free
Heidi AI

Heidi. By your side.

© 2026 Heidi. All rights reserved.

Specialties

  • Family Medicine

  • Specialists

  • Nurses

  • Mental Health

  • Allied Health

  • Dentists

  • Veterinarians

  • Trainees

Compliance

  • Safety

  • Trust Center

  • AU/NZ

  • Canada

  • UK

  • GDPR

  • HIPAA

Product

  • Pricing

  • Changelog

  • Downloads

  • Heidi Guides

  • Help Centre

  • System Status

  • System Requirements

  • AI Instructions

About Us

  • Contact Us

  • Company

  • Customer Stories

  • Media

  • Open Roles

    10+
  • People

  • Partnerships

Resources

  • Blog

  • ROI Calculator

  • Resource Centre

  • Template Community

  • FAQs

Legal

  • Privacy Policy

  • Terms of Service

  • Usage Policy

  • UKGDPR Policy

  • Accessibility

Ask AI about Heidi:

Secure your customers' data

Lawfulness, Fairness, and Transparency

We process all personal data lawfully, fairly, and in a transparent manner in relation to the data subject.

Data Minimization

We process all personal data lawfully, fairly, and in a transparent manner in relation to the data subject.

Consent

Consent is important, and we support clinicians in getting clear agreement from patients before using Heidi in a consultation. That’s part of the normal clinical process. From a data protection perspective, Heidi doesn’t rely on consent under GDPR. Instead, we process data on the controller’s instructions, under Article 6(1)(e) (public task) or Article 6(1)(f) (legitimate interests), and Article 9(2)(h) for health data.

Rights of the Data Subject

We fully support the rights of individuals under GDPR, including the right to access, correct, delete, and restrict processing of their data, the right to data portability, and the right to object.

Data Protection by Design and by Default

We implement appropriate technical and organizational measures that ensure and demonstrate that we process personal data in compliance with GDPR. This includes measures to protect data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

Data Transfer

We ensure your data remains within the EU/EEA and is protected in accordance with GDPR requirements.

Data Breach Notification

We ensure your data remains within the EU/EEA and is protected in accordance with GDPR requirements.

Data Protection Officer (DPO)

We ensure your data remains within the EU/EEA and is protected in accordance with GDPR requirements.

Compliance

GDPR

Heidi diligently adheres to GDPR regulations, safeguarding your personal data with strict protocols and robust security measures, reinforcing trust and accountability in our operations.

Get Heidi free
An unlocked padlock icon above a password field with asterisks on a monitor screen.

Related articles

Compliance
Compliance illustration
Compliance
Automation Bias in Healthcare and Heidi

LJ Acallar

April 20, 2026•Listen
Compliance
Compliance illustration
Compliance
Healthcare Data Processing and Encryption at Heidi

LJ Acallar

March 30, 2026
Compliance
Compliance illustration
Compliance
Informed Consent in Healthcare and Heidi

LJ Acallar

February 3, 2026•1 min read•Listen
  • Heidi AI is a SOC 2 Type 2-Certified Clinical AI Company
  • Heidi AI is a GDPR-Compliant Ambient AI Scribe
  • Heidi AI is an ISO 27001-Certified Clinical AI Company
  • Heidi is APP Compliant!

Frequently Asked Questions about GDPR Compliance

Yes. From ensuring your personal data remains within the EU/EEA and is protected in accordance with GDPR requirements to lawful, fair, and transparent data processing and transfer, Heidi safeguards your personal data with strict protocols and robust security measures. We use a continuous compliance management system that makes sure we are always vigilant for our GDPR compliance, instead of a point in time audit which can lead to vulnerabilities in between audits. Learn more about our GDPR compliance practices here.