GDPR Compliance at Chartnote | Data Privacy & Security

🛡️ GDPR Compliance at Chartnote

Overview


At Chartnote, protecting user privacy and securing personal data is a top priority. As part of our ongoing commitment to global data protection standards, we adhere to the General Data Protection Regulation (GDPR) — a comprehensive privacy law governing how personal data from individuals in the European Union (EU) and United Kingdom (UK) is collected, processed, and transferred.


This policy ensures that even when we process data outside the EU/UK, it remains protected through robust contractual and technical safeguards.


How Chartnote Ensures GDPR Compliance


1. Data Transfers Outside the EU/UK


Chartnote may store or process personal data in countries outside the EU or UK. When doing so, we take steps to ensure the data remains protected to the same standard required under GDPR.


We implement the following safeguards:

  • Standard Contractual Clauses (SCCs):

    Chartnote uses European Commission-approved contractual obligations to legally safeguard data transfers outside the EU/UK.

  • Adequacy Decisions:

    When available, we rely on adequacy decisions from the European Commission or UK government for countries deemed to offer an adequate level of data protection.

  • Additional Measures:

    Where required, Chartnote adopts supplementary technical and organizational measures—such as encryption, access controls, and data minimization—to maintain data integrity and confidentiality.


2. Transparency and User Rights


We believe in full transparency about how data is used. When you use Chartnote’s services, you acknowledge that your data may be transferred and stored securely outside your home country.


If you have any concerns or questions about Chartnote’s data protection or transfer practices, you can contact our Privacy team at hello@chartnote.com.


3. Staff Training and Compliance


All Chartnote team members undergo GDPR and CCPA training through Vanta, our compliance partner.

These training modules cover:

  • Data protection principles

  • Handling personal and sensitive data

  • Incident response and breach reporting

  • Responsibilities under GDPR and CCPA


Completion of these trainings is mandatory for all team members to ensure compliance and awareness across the organization.


Related Policies and Resources


Summary


Chartnote’s GDPR compliance framework is built around transparency, security, and accountability. Through SCCs, data protection measures, and regular staff training, we ensure all data handled by Chartnote meets the highest privacy standards—no matter where it’s processed.


    • Related Articles

    • Chartnote Privacy and Security (HIPAA, PIPEDA, GDPR, SOC 2)

      At Chartnote, the trust of clinicians and patients is our top priority. Security is at the core of everything we create. We adhere to HIPAA, PIPEDA, GDPR, and SOC 2 standards to ensure that all data we collect and process is safeguarded at every ...
    • 🇨🇦 Understanding Consent Laws for Recording Clinical Visits in Canada

      Overview When using Chartnote’s AI Scribe feature to record and transcribe clinical visits in Canada, it is essential to understand the legal framework around recording conversations and handling personal health information. This article outlines key ...
    • Using Device Unlock (Face Recognition, Fingerprint, PIN) with Chartnote Mobile App

      Applies to: Chartnote Mobile App (Android and iOS) Overview To protect patient data and maintain security, Chartnote Mobile App uses your device’s existing secure unlock methods—such as face recognition, fingerprint, PIN, or pattern lock. This ...
    • Control access to camera and microphone on iPhone

      This guide provides step-by-step instructions on how to control access to the camera and microphone on an iPhone. By following these steps, users can easily manage which apps have access to these features, enhancing privacy and security. Step-by-step ...
    • How to Create and Use Snippets in Chartnote

      A comprehensive, step‑by‑step tutorial for clinicians and staff who want to build smart, reusable text blocks ("snippets") and deploy them quickly in Chartnote and in web‑based EHRs. Create your first snippet Open Library → Snippets From Chartnote on ...