Privacy Policy
How we handle information
Shifaya is built for clinical environments, so how we handle information is not an afterthought. This page explains what we collect, how it is used, and the principles behind it.
Last updated: August 2026
Overview
This Privacy Policy explains how Shifaya (“Shifaya,” “we,” “us”) collects, uses, and protects information in connection with our website and our ambient clinical documentation platform.
Shifaya is designed for use by healthcare organisations and their clinicians. If you are a patient, your care team's use of Shifaya is governed by their own policies and their agreement with us, in addition to this policy.
Information we collect
Clinical encounter data. When a clinician uses Shifaya during a consultation, we may securely capture and process audio from the encounter, along with the resulting transcripts, structured documentation, and clinician corrections, on behalf of the healthcare organisation operating Shifaya.
Contact information. When you get in touch with us through this website, we collect what you provide directly - name, email address, phone number, area of interest, and message content.
Website usage information. Like most websites, our marketing site may collect basic technical information, such as browser type and general usage patterns, needed to operate and improve it. See “Cookies” below.
How we use information
We use clinical encounter data solely to provide the documentation service to the healthcare organisation that has engaged Shifaya: generating a structured clinical draft, presenting it to the clinician for review, and returning approved information to the appropriate record system.
We use contact information you submit through this website only to respond to your enquiry.
AI models and training
Hospital and patient information is not used to train external, general-purpose AI models. Where system improvement relies on real usage, it is designed to happen through configuration, clinician feedback, and quality review - not by feeding identifiable patient data into uncontrolled retraining processes.
Clinician oversight
Every record Shifaya generates is treated as a draft. Clinical information becomes part of the official medical record only after a clinician has reviewed, corrected where necessary, and explicitly approved it.
Shifaya does not independently diagnose patients, initiate treatment, or release information into a patient record without that approval.
Data security
We are building Shifaya around a set of security practices consistent with the requirements set out in the hospital procurement specifications that inform our product design:
- Encryption of data in transit and at rest
- Audit logging of relevant system and user actions
- Automatic deletion of recordings and transcripts after they have been processed into the clinical record
Data retention
Clinical encounter recordings and transcripts are retained only for as long as needed to generate and validate the resulting documentation, after which they are eligible for automatic deletion.
Structured clinical documentation itself is retained according to the policies of the healthcare organisation operating Shifaya, since that information becomes part of their medical record. Contact form submissions are retained only as long as needed to respond to your enquiry.
Sharing of information
We do not sell personal or patient information. We may share information with service providers who help us operate our infrastructure, under agreements that require them to protect it and restrict their use of it to the services they provide us. We may also disclose information where required by law.
Your rights
Depending on where you are located and your relationship to Shifaya, you may have rights to access, correct, or request deletion of information we hold about you.
If you are a patient, these requests are usually best directed to your healthcare provider first, since they control the medical record. You can also contact us directly at info@shifaya.com.
Cookies
This website uses only the cookies necessary for it to function correctly. We do not use third-party advertising or cross-site tracking cookies.
International data transfers
If information is transferred across borders in the course of operating Shifaya, we work with the healthcare organisations we serve to do so in a manner consistent with applicable data protection requirements.
Changes to this policy
We may update this Privacy Policy as Shifaya's product and practices evolve. We will update the “Last updated” date at the top of this page when we do.
Contact us
Questions about this policy or how Shifaya handles information can be sent to info@shifaya.com or through our contact page.