●OUI / RADDICTATE
How it works RadTranscribe Guides Pricing Contact Request free trial
How it works RadTranscribe Guides Pricing Contact Feedback

Legal & policies

Terms and Conditions Privacy & Data-Processing Notice Refund Policy Cancellation & Delivery Policy Ownership Statement Acceptable Use Policy Clinical Use & Safety Disclaimer

Privacy & Data-Processing Notice · version 1.2 · effective 2026-08-29

Privacy & Data-Processing Notice

This Notice explains how OUI Technologies (SMC-Private) Limited ("OUI") handles information when you use the Service (as defined in the Terms of Service — including RadDictate, RadScribe, RadTranscribe, and OUI's offline/locally-installed products). It forms part of your Agreement. Capitalised terms have the meaning given in the Terms of Service.

1. Our role

  • For your account and usage information, OUI acts as the controller.
  • For Patient Data that you input, OUI acts as a processor on behalf of you or your Institution (the controller). Where you use the Service for an Institution, identifiable Patient Data is governed by the separate agreement between OUI and that Institution.

2. Information we process

  • Account / identity: your name or identifier, email, Institution (if any), role, and authentication data (handled via Google Identity Platform).
  • Audio dictations: transmitted for transcription; not stored by OUI after processing.
  • Transcripts / reports: stored to provide history and sync across your devices, isolated to your account — end-to-end encrypted on your device before upload, so OUI stores only ciphertext (see Section 9).
  • Templates: stored and synced to your account so they follow you across devices. Templates are not end-to-end encrypted and must not contain patient identifiers.
  • Payment data: plan, amount, currency, payment status, and transaction references. Card and wallet numbers are collected and processed by our payment provider (currently Safepay); OUI never sees or stores your card number.
  • Website enquiries: name, email, role, organization, and message you submit through ouitech.net forms (trial requests, contact, feedback), protected by Cloudflare Turnstile anti-bot checks.
  • Usage / technical: request counts, timestamps, model/provider used, device and log data needed to operate and secure the Service. **We do not log audio, transcripts, or report text.**

3. Patient Data and your responsibility

The cloud Service is for de-identified use. You must not input direct patient identifiers into it, and client-side encryption of a report or label does not make identifiable input permitted. OUI processes identifiable Patient Data only where a signed written agreement expressly authorises it — an Identifiable Use Addendum with an independent professional, or an MSA/DPA with the controlling Institution — and only within the product and scope that agreement names (see Terms §7 and the AUP). Where you input Patient Data without that authorisation, you do so in breach of the Agreement and as the responsible party.

4. Purposes and legal bases

We process information to: provide and secure the Service; transcribe and format dictations; sync your history/templates; support, debug, and improve service reliability; comply with law; and enforce our terms. Legal bases include performance of our contract with you, our legitimate interests in operating and securing the Service, your consent where required, and — for Patient Data — the controller's lawful basis as represented by you or your Institution, consistent with applicable Pakistani law, including the Prevention of Electronic Crimes Act 2016 where relevant and any data-protection legislation as enacted.

5. AI processing and sub-processors

Cloud transcription and formatting are currently performed using Google Cloud Vertex AI (Gemini models) within OUI's Google Cloud project. Google acts as our sub-processor under the Google Cloud Data Processing Addendum (CDPA), which OUI has accepted. OUI may change the specific models used, and may engage additional or replacement sub-processors that provide materially equivalent contractual and technical protections (including no-training commitments equivalent to Section 6); material changes to sub-processors will be reflected in this Notice and, where they materially affect Patient Data processing, notified under Section 14.

5A. Offline / locally-installed products

Some OUI products (for example offline transcription applications, and RadTranscribe when used with the local provider) process dictation entirely on your device: audio, transcripts, and report text are not transmitted to OUI or any cloud provider by those products. For such products OUI processes only the information needed to license and operate them — such as account/licence identity, activation and entitlement checks, version and update checks, and (only if you opt in) crash or diagnostic data that excludes Content. Where an offline product is used fully standalone (no account), OUI receives no usage data from it beyond any activation/licence verification described at purchase.

5B. Other service providers

The Service also relies on: Cloudflare (delivery of the ouitech.net website and Turnstile anti-bot protection on its forms, which processes IP and browser signals); Google Gmail / Workspace (transactional email such as verification, renewal, and support messages); Safepay (payment processing — Safepay, not OUI, collects your card or wallet details); and the push-notification service chosen by your browser or device (optional; payloads never contain report content). Each receives only what it needs to perform its function.

6. No model training; retention by the AI provider

  • Customer prompts and responses are not used to train the AI provider's models (Vertex AI default).
  • OUI has disabled prompt/response caching at the project level, and Google has approved OUI's exception from abuse-monitoring prompt/response logging for OUI's project, effective 20 July 2026 — so prompts and responses are not retained for that routine abuse monitoring. OUI does not claim unconditional "zero data retention": Google may still process and retain limited data as needed to operate and secure its service under its then-current terms.

7. International transfers

Processing occurs on Google Cloud infrastructure, which may include Singapore (asia-southeast1) and Google's global endpoints. Transfers are made under the CDPA and applicable safeguards. If your or your Institution's requirements demand local-only processing, use the offline / local provider, which does not transmit data to the cloud.

8. Retention and deletion (by OUI)

  • Audio: not retained after processing.
  • Reports (encrypted): retained only for the history window set on your account (1-60 days; default 14), after which they are deleted automatically. You may delete them sooner in-product.
  • Templates: kept until you delete them or your account is closed.
  • Phone-dictation session records (a random session ID, state, timestamps, and the end-to-end-encrypted result): expire within 24 hours.
  • Account closure: when your account is closed, any remaining copies are deleted within 30 days. The Service is not a system of record — keep authoritative records in your hospital/clinic information system.
  • Acceptance and security logs: retained as needed for legal/audit purposes. You may delete reports in-product and may request account deletion at info@ouitech.net.

9. Security; end-to-end encryption of saved reports

We use encryption in transit (TLS) and at rest, account-level access isolation, least-privilege access controls, and safeguards designed to keep audio/transcript/report content out of application logs. Saved report content (body and title) and any report label are end-to-end encrypted: they are encrypted on your device with AES-256-GCM under a per-user key that is itself wrapped by a key derived from your login password. Our servers store only ciphertext and the wrapped key, and refuse unencrypted report writes — OUI cannot read your saved reports. Templates, account data, settings, and usage data are not end-to-end encrypted. Encryption protects saved history, not live processing: audio and text are necessarily readable in service memory while a transcription or formatting request is being processed. If you reset your password without the old one, existing encrypted history becomes unreadable and OUI cannot restore it. No system is perfectly secure; we cannot guarantee absolute security.

10. Your and patients' rights

Subject to applicable law, you may access, correct, or delete your account data. Requests relating to Patient Data should be directed to the controller (you or your Institution); where OUI is processor, we will assist the controller as required. Contact info@ouitech.net.

11. Local storage / cookies

The extension and mobile app store data locally on your device (e.g. cached templates, session tokens, offline history) to function. You can clear this via the app or your device settings.

12. Data breach

If we become aware of a personal-data breach affecting your data, we will act in accordance with applicable law and, where OUI is processor, notify the relevant controller without undue delay.

13. Children

The Service is for healthcare professionals and is not directed to children.

14. Changes

We may update this Notice; material changes will require re-acceptance (see Terms §16).

15. Contact

OUI Technologies (SMC-Private) Limited, House No. 286, Street 2, Block XX, Phase 3, DHA Lahore, Punjab, Pakistan · info@ouitech.net.

OUI Technologies (SMC-Private) Limited · Company reg. no. 0346192 · House No. 286, Street 2, Block XX, Phase 3, DHA Lahore, Punjab, Pakistan · +92 371 3314155 · info@ouitech.net

© 2026 OUI Technologies (SMC-Private) Limited — SECP-registered, Pakistan. Company reg. no. 0346192. House No. 286, Street 2, Block XX, Phase 3, DHA Lahore, Punjab, Pakistan · +92 371 3314155 · info@ouitech.net Terms · Privacy · Refunds · Cancellation & delivery · Ownership · Acceptable use · Contact