GDPR Privacy Policy
Last updated: July 20, 2026
Version: 1.0
Important Notice: This Privacy Policy specifically addresses the requirements of the General Data Protection Regulation (GDPR) (EU) 2016/679 and applies to all users within the European Economic Area (EEA), United Kingdom, and Switzerland. For our general privacy policy, please visit our Privacy Policy page.
1. Data Controller Information
28labs Inc. ("Birch", "we", "us", "our") is the data controller responsible for the processing of your personal data through the Birch website and AI-powered patient communication platform (the "Service").
Contact Details:
28labs Inc.
Email: support@getbirch.com
Data Protection Officer: support@getbirch.com
Support: /support
2. EU Representative
In accordance with Article 27 of the GDPR, we have appointed the following representative in the European Union:
The appointment of our EU representative is in progress. Until it is completed, EU data subjects can direct all GDPR inquiries and requests to us directly at support@getbirch.com, and we will respond within the timelines the GDPR requires. This section will be updated with the representative's contact details once appointed.
3. Categories of Personal Data We Process
We process the following categories of personal data:
3.1 Account Information:
- Full name
- Email address
- Professional license number
- Medical specialty
- Practice location
- Account credentials (encrypted)
- Profile information
3.2 Special Categories of Personal Data (Health Data):
- Recordings of calls handled through the Service (audio)
- Call and conversation transcripts
- Messages exchanged via text, chat, or email
- Patient health information (as processed by healthcare professionals)
- Medical terminology and diagnoses
- Treatment plans and medical histories
3.3 Technical Data:
- IP address
- Device information (type, operating system, browser)
- Usage logs and analytics
- Cookies and similar tracking technologies
- Session information
- Error logs and crash reports
3.4 Communication Data:
- Support tickets and inquiries
- Email communications
- Feedback and surveys
- Marketing preferences
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under Article 6 and Article 9 of the GDPR:
4.1 Contract Performance (Article 6(1)(b)):
- Creating and managing your account
- Providing AI-powered patient communication services
- Processing payments and billing
- Customer support services
4.2 Legitimate Interests (Article 6(1)(f)):
- Improving service quality and accuracy
- Fraud prevention and security measures
- Internal research and analytics
- Direct marketing to existing customers (with opt-out option)
4.3 Legal Obligations (Article 6(1)(c)):
- Compliance with healthcare regulations
- Tax and accounting requirements
- Response to legal requests and court orders
- Data breach notifications
4.4 Consent (Article 6(1)(a) and Article 9(2)(a)):
- Marketing communications (where required)
- Non-essential cookies and analytics
- Processing of special categories of data (health data) where explicit consent is required
4.5 Processing of Health Data (Article 9(2)):
- Explicit consent (Article 9(2)(a))
- Provision of healthcare services (Article 9(2)(h))
- Public interest in public health (Article 9(2)(i))
- Scientific research purposes (Article 9(2)(j))
5. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
5.1 Right of Access (Article 15):
You have the right to obtain confirmation as to whether we process your personal data and, if so, access to the personal data and information about how we process it.
5.2 Right to Rectification (Article 16):
You have the right to request correction of inaccurate personal data and to have incomplete personal data completed.
5.3 Right to Erasure ("Right to be Forgotten") (Article 17):
You have the right to request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or in other circumstances set out in Article 17.
5.4 Right to Restriction of Processing (Article 18):
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or object to our processing.
5.5 Right to Data Portability (Article 20):
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
5.6 Right to Object (Article 21):
You have the right to object to processing based on legitimate interests, direct marketing, and processing for research and statistical purposes.
5.7 Rights Related to Automated Decision-Making (Article 22):
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal or similarly significant effects.
5.8 Right to Withdraw Consent:
Where processing is based on consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
6. How to Exercise Your Rights
To exercise any of your rights under GDPR, please:
- Email us at support@getbirch.com
- Use our Data Subject Request Form at /support
- Contact our Data Protection Officer at support@getbirch.com
We will respond to your request within one month of receipt. In complex cases, we may extend this period by two additional months, but we will inform you of any such extension.
7. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), particularly the United States where our servers are located. We ensure appropriate safeguards for such transfers:
- Standard Contractual Clauses (SCCs): We use EU-approved standard contractual clauses for data transfers to countries without an adequacy decision
- Technical and Organizational Measures: Implementation of appropriate security measures to protect your data during transfer
- Supplementary Measures: Additional safeguards including encryption, access controls, and security assessments
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Account Data: Retained for the duration of your account plus 30 days after deletion request
- Health Data/Medical Records: Retained in accordance with applicable healthcare regulations (typically 7-10 years)
- Technical Logs: Retained for 12 months for security and debugging purposes
- Marketing Data: Retained until you unsubscribe or withdraw consent
- Legal Compliance Data: Retained as required by applicable laws and regulations
9. Data Security Measures
We implement comprehensive technical and organizational measures to protect your personal data:
- Encryption: AES-256 encryption for data at rest and TLS 1.3 for data in transit
- Access Controls: Role-based access control (RBAC) and multi-factor authentication
- Pseudonymization: Where possible, we pseudonymize personal data
- Regular Security Assessments: Penetration testing and vulnerability assessments
- Employee Training: Regular data protection and security awareness training
- Incident Response: Established procedures for data breach detection and notification
- Data Minimization: We only collect and process data necessary for specified purposes
10. Data Protection Impact Assessments (DPIA)
We conduct Data Protection Impact Assessments for processing operations likely to result in high risk to data subjects' rights and freedoms, particularly:
- Large-scale processing of health data
- Implementation of new AI/ML models for conversation handling
- Introduction of new features affecting data processing
- Changes to data sharing or transfer arrangements
11. Joint Controller Arrangements
In certain circumstances, we may act as a joint controller with healthcare organizations:
- Integrated EHR Systems: When our Service integrates with electronic health record systems, we may jointly determine the purposes and means of processing
- Clinical Research: For anonymized research initiatives with healthcare institutions
- Quality Improvement Programs: When collaborating on healthcare quality metrics
For joint controller arrangements, we establish clear agreements defining:
- Respective responsibilities for GDPR compliance
- Transparent information about roles to data subjects
- Points of contact for data subject requests
- Allocation of liability and indemnification
12. Privacy by Design and Default
Birch implements Privacy by Design principles throughout our Service:
- Proactive not Reactive: We anticipate and prevent privacy invasions before they occur
- Privacy as Default: Maximum privacy protection is delivered automatically without requiring action from the user
- Full Functionality: We accommodate all legitimate interests without unnecessary trade-offs
- End-to-End Security: Secure lifecycle management from data collection to deletion
- Visibility and Transparency: All stakeholders can verify our privacy practices
- User-Centric Design: Privacy features are designed with the user's interests paramount
- Privacy Embedded: Privacy considerations are integral to system design, not add-ons
13. Records of Processing Activities
In accordance with Article 30 of the GDPR, we maintain comprehensive records of our processing activities including:
- Name and contact details of the controller and DPO
- Purposes of the processing for each category of data
- Description of categories of data subjects and personal data
- Categories of recipients including those in third countries
- Details of international transfers and safeguards
- Retention periods for each category of data
- General description of technical and organizational security measures
These records are available to supervisory authorities upon request and are regularly reviewed and updated.
14. Lawful Basis Assessment
We have conducted detailed lawful basis assessments for each processing activity:
| Processing Activity | Lawful Basis | Legitimate Interest (if applicable) |
|---|---|---|
| Account creation and management | Contract (6(1)(b)) | N/A |
| AI conversation and communication processing | Contract (6(1)(b)) + Healthcare (9(2)(h)) | N/A |
| Service improvement analytics | Legitimate interests (6(1)(f)) | Improving conversation quality and user experience |
| Security monitoring | Legitimate interests (6(1)(f)) | Protecting systems and data from unauthorized access |
| Marketing to existing customers | Legitimate interests (6(1)(f)) | Informing about relevant features and updates |
| Legal compliance | Legal obligation (6(1)(c)) | N/A |
15. Brexit-Specific Provisions
For users in the United Kingdom:
- This policy complies with the UK GDPR as incorporated into UK law
- References to "GDPR" include the UK GDPR where applicable
- Our UK representative can be contacted at support@getbirch.com
- UK users may lodge complaints with the Information Commissioner's Office (ICO)
- International transfers from the UK are covered by appropriate safeguards
We use the UK's International Data Transfer Agreement (IDTA) or the EU SCCs with the UK Addendum for transfers from the UK to countries without adequacy decisions.
16. Third-Party Data Processors
We work with carefully selected third-party processors who assist us in providing our services. All processors are bound by data processing agreements in accordance with Article 28 of the GDPR:
- Cloud Infrastructure: Amazon Web Services (AWS) - for secure data storage
- Analytics: Privacy-compliant analytics providers
- Communication: Email service providers for transactional emails
- Payment Processing: PCI-DSS compliant payment processors
A complete list of our data processors is available upon request at support@getbirch.com.
12. Children's Privacy
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to delete that information.
13. Cookies and Tracking Technologies
We use cookies and similar tracking technologies in compliance with the ePrivacy Directive. For detailed information about our use of cookies, please refer to our Cookie Policy.
14. Automated Decision-Making and Profiling
We use automated processing for certain aspects of our Service:
- AI Conversation Handling: Automated voice and text interactions, including speech recognition and response generation using machine learning
- Medical Terminology Recognition: Automated identification of medical terms
- Security Monitoring: Automated detection of potential security threats
These processes do not constitute automated decision-making that produces legal or similarly significant effects. Healthcare professionals retain full control over all medical decisions.
15. Data Breach Notification
In the event of a personal data breach, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (unless unlikely to result in risk)
- Notify affected data subjects without undue delay if the breach is likely to result in high risk to their rights and freedoms
- Document all breaches and our response actions
- Implement measures to prevent future occurrences
21. Your Right to Lodge a Complaint
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with a supervisory authority. You may contact:
- Your local data protection authority in your EU member state
- The Irish Data Protection Commission (as we operate in Ireland)
- Any supervisory authority of your habitual residence, place of work, or place of alleged infringement
22. Changes to This Policy
We may update this GDPR Privacy Policy from time to time. When we make material changes:
- We will notify you via email or prominent notice within the Service
- We will update the "Last updated" date at the top of this policy
- We will maintain a version history for transparency
- For significant changes affecting the legal basis of processing, we may seek renewed consent where required
23. Contact Information
For any questions, concerns, or requests regarding this GDPR Privacy Policy or our data protection practices:
Data Controller:
28labs Inc.
Email: support@getbirch.com
Support: /support
Data Protection Officer:
Email: support@getbirch.com
EU Representative:
Email: support@getbirch.com
This GDPR Privacy Policy is provided in English. In case of any discrepancies between translated versions and the English version, the English version shall prevail. This policy complies with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).