Document ID: O-06
Version and date: 2026-08-21.1 - 21 August 2026
Provider: FlowDule ApS, CVR 46273397
Contact: privacy@flowdule.com
In short: FlowDule’s AI is optional documentation support. It prepares drafts, but does not make professional decisions. A competent user must check and actively approve the result before it is saved, shared or used.
1. Who this information is for
This information is for FlowDule’s business customers, practitioners, administrators and other users who are considering or using an AI function. It may also be used by the customer’s clients to understand FlowDule’s technical role.
The customer decides whether an approved AI function is to be activated, for which documented purpose and for which users. The fact that a function exists in the product does not mean that it is activated or approved for all data types.
2. What AI may help with
Following separate activation, FlowDule may offer the following limited forms of documentation support:
-
linguistic formatting and improvement of the user’s own text;
-
summarising and structuring of material;
-
translation with checking against the original;
-
OCR that converts document images into text;
-
transcription of audio, where recording and processing are lawful;
-
drafts of reports or other documents based on selected sources.
The specific function, model, supplier, data category, region and retention must appear in the customer’s accepted instruction annex.
3. What AI may not be used for
FlowDule’s launch scope does not permit AI for:
-
independent diagnosis, triage or risk scoring;
-
selection, alteration or recommendation of treatment;
-
decisions on access to treatment, a service or any other individual right;
-
automatic completion or signing of records without active human approval;
-
hidden profiling, emotion recognition or biometric categorisation;
-
research, marketing, model training or general product development on the customer’s client or record data;
-
reuse of output for other customers or for purposes other than the customer’s documented instructions.
A new function within any of these areas requires a new legal classification, DPIA review, AI Act assessment, technical testing and express management and customer acceptance. It is not covered by this version.
4. Human oversight
AI output is always a draft. Before use, a competent user must:
-
check that the material relates to the right person and case;
-
compare the output with the original text, audio or other source material;
-
check facts, negations, figures, dates, names, medical or professional terms and material omissions;
-
correct or reject uncertain or misleading content;
-
take independent responsibility for the final text and the professional action;
-
actively approve before the result is saved, shared or used.
FlowDule must clearly mark AI drafts and the moment of approval in the user interface. A missing active approval step may not be replaced by general wording in the terms.
5. Data and data protection roles
The customer is the controller for its processing of client and record information and determines the basis for processing under Article 6 GDPR and, where relevant, Article 9, as well as any national legal basis. FlowDule processes the information as a processor under the Data Processing Agreement and the customer’s accepted instruction annex.
Depending on the function, the processing may cover record text, free text, document images, audio, transcription, prompt, output and necessary technical metadata. The user must limit input to what is necessary for the approved purpose.
FlowDule may not use the customer’s client or record data for its own AI purposes, training of general models, marketing or cross-customer analysis.
6. Suppliers and technical processing
The planned supplier chain uses AWS services under FlowDule’s AWS agreement:
| Function | Service | Data processed | Release status |
|---|---|---|---|
| Generative text | Amazon Bedrock with an approved model, currently planned as Anthropic Claude via AWS | Prompt, selected source text and output | Released gradually; requires separate activation and the customer’s instructions |
| Speech to text | Amazon Transcribe | Audio and transcription | Separate activation and the customer’s instructions required |
| OCR | Amazon Textract | Document image and derived text | Separate activation and the customer’s instructions required |
| Translation | Amazon Translate | The text the user chooses to translate | Separate activation and the customer’s instructions required |
The actual model versions, AWS regions and any inference destinations may change and must therefore not be inferred from the table alone. The binding combination appears in the accepted version of Sub-processors and suppliers and the customer’s instruction annex.
7. Region, retention and model training
For each AI function, FlowDule must document before activation:
-
the effective AWS account, service, model and version;
-
all processing and inference regions as well as potential remote support;
-
allowed_modes, provider sharing and the effective retention setting; -
whether prompt, input or output is retained by the supplier and, if so, why and for how long;
-
that the information is not used for the supplier’s or FlowDule’s general model training;
-
deletion, logs, sub-suppliers, transfer basis and supplementary measures.
A marketing label such as “EU region”, “store=false” or “no training” is not sufficient evidence without verification of the effective account and model configuration. If the required documentation is not available, the function remains deactivated for client, record and health information.
8. Quality, limitations and errors
AI can hallucinate, misunderstand context, overlook negations, confuse people, distort figures or dates, translate professional terms incorrectly and reproduce bias from the model or the source material. A fluent and convincing answer is not proof that the answer is correct.
FlowDule tests each use case in the relevant language and professional field with representative, lawful test data. The test establishes accepted error thresholds, stop criteria and necessary user warnings. Serious or repeated errors may result in immediate deactivation of the affected model or function.
Users can report AI errors via support@flowdule.com. Security incidents and possible exposure of personal data are reported immediately via security@flowdule.com.
9. Information for the client
The customer must assess when a client is to be informed about the use of AI under GDPR, professional rules and the AI Act. The customer’s local text must at a minimum give an accurate account of:
-
the purpose for which AI is used;
-
what information is processed;
-
that output is checked and approved by a human;
-
relevant suppliers, regions, retention and transfers;
-
how the client can contact the customer about rights or questions.
If a person interacts directly with an AI system, that person must be informed of this, unless it is obvious in the specific context. FlowDule has not approved a client-facing AI chatbot within the launch scope.
10. Automated decisions and profiling
FlowDule’s approved AI use cases do not make decisions based solely on automated processing that have legal effect or similarly significant effect for a person. The customer may not circumvent this by making an AI recommendation effectively binding without a genuine, competent and independent human assessment.
If a future function could affect diagnosis, treatment, access to services, insurance, employment or other significant matters, it must be stopped at the release gate and assessed separately under Article 22 GDPR, the AI Act and any rules on medical devices.
11. AI literacy and user access
Only users with a relevant role and completed training may be granted access. The training covers at a minimum:
-
the function’s intended and prohibited use;
-
hallucination, bias and source checking;
-
data minimisation and handling of special categories;
-
human approval and professional responsibility;
-
error, incident and security reporting.
The training is documented and repeated on material changes and otherwise in accordance with the internal training plan. FlowDule and the customer allocate responsibility for training in onboarding and in the customer annex.
12. Rights and contact
If you are a client of a practitioner, questions about your record, access, rectification, erasure or basis for processing must be directed to the practitioner or the clinic. FlowDule assists the customer in accordance with its instructions.
If the question concerns FlowDule’s own processing, you can contact privacy@flowdule.com. Further information is available in the Privacy Policy, the Data Processing Agreement and Sub-processors and suppliers.