Privacy information for customers, prospects, and transcription teams.

This policy explains what HeliQore collects, why it is used, how health-sensitive workflow data is handled, and how to contact us about privacy questions or requests.

1. Who We Are

HeliQore provides medical transcription and transcript-formatting workflows for English-speaking medical, specialist, and medico-legal documentation environments. In this policy, HeliQore, we, us, and our refer to the HeliQore service and website.

For privacy questions, access requests, correction requests, or complaints, contact privacy@heliqore.com.

2. Scope Of This Policy

This policy applies to the public website, the authenticated HeliQore transcription workspace, and related support, billing, and account interactions. It does not override any enterprise agreement, data processing addendum, Business Associate Agreement, or other written contract that expressly applies to a customer account.

3. Information We Collect

4. Sensitive Information And Health Data

Because HeliQore is designed for medical transcription and medico-legal workflows, content submitted to the service may include sensitive information such as health information, patient identifiers, specialist dictation, chronology-heavy reports, or other confidential material. Customers are responsible for ensuring they are authorised to submit that material to HeliQore and that the workflow they choose is suitable for their regulatory and contractual obligations.

5. Why We Use Information

  • To provide transcription, formatting, storage, retrieval, and account-management features.
  • To authenticate users, manage subscriptions, and administer billing.
  • To protect the service, investigate issues, detect abuse, and monitor reliability.
  • To respond to support requests, demos, and enterprise security questions.
  • To comply with legal obligations and maintain business records.

6. How HeliQore Processes Customer Content

HeliQore uses API-based transcription and formatting workflows running on AWS infrastructure and OpenAI API services. Uploaded audio is sent through the product workflow to generate transcript text, and transcript text may then be sent through a formatting workflow to improve punctuation, paragraphing, and report structure.

HeliQore does not use customer content to train its own models. Customer workflow content is processed to provide the service requested by the customer, not to build a public dataset or consumer AI product.

7. Subprocessors And Service Providers

HeliQore uses a limited number of service providers to support hosting, transcription workflows, and subscription billing. Current public summaries are published on the Subprocessors page and in the Trust Center.

8. Cross-Border Processing And Storage Regions

Depending on deployment and customer configuration, HeliQore may process or store workflow data in Australia, the United States, the United Kingdom, Canada, Ireland, or New Zealand. The current product codebase supports region-specific storage configurations for those markets.

If a customer requires a specific residency or cross-border arrangement, that should be discussed before uploading regulated or contract-sensitive material. Not every plan or workflow configuration will necessarily support every residency requirement.

9. Retention And Deletion

HeliQore is designed around limited retention rather than indefinite storage. Based on the current product implementation:

  • Uploaded audio under `uploads/` is configured to expire after 30 days.
  • Temporary transcription and formatted output under `transcribe-output/` and `formatted-output/` is configured to expire after 1 day as a backstop.
  • Successful retrieval deletes the formatted output immediately after delivery to the authenticated client.
  • Upload grants are purged after 2 days, job metadata after 7 days, and usage metadata after 30 days by default.

Retention settings may change over time as the product evolves, but HeliQore aims to keep operational data only for as long as it is reasonably required for service delivery, security, billing, or legal obligations.

10. Security Measures

HeliQore uses authenticated access controls, private cloud storage, TLS, access-scoped infrastructure roles, logging, and edge protection controls. More detail is available on the Security & Compliance and Trust Center pages.

11. Cookies, Logs, And Website Tracking

The public website and authenticated app use technical functions and security logging needed to deliver pages, maintain sessions, and protect the service. If HeliQore introduces non-essential analytics, advertising technologies, or broader tracking tools in future, this policy and any required consent controls will be updated before those tools are relied on.

12. Access, Correction, And Complaints

You can contact HeliQore to request access to personal information we hold about you, request corrections, or raise a privacy complaint. We will review and respond in line with applicable obligations. If you are in Australia and believe your complaint has not been handled appropriately, you may also have the right to complain to the Office of the Australian Information Commissioner.

13. HIPAA / BAA Workflows

If HeliQore and a customer enter into a signed Business Associate Agreement for an approved workflow, that BAA may add specific privacy, security, and breach-notification obligations for PHI handled on that customer's behalf. Self-service website use and ordinary checkout do not by themselves create a BAA.

14. Changes To This Policy

We may update this policy from time to time to reflect product, legal, or operational changes. When we do, we will update the date at the top of the page and publish the revised version on heliqore.com.