Hilbi IQ · data processing
Where your data goes, in writing
Patient data stays in the EU and never trains a foundation model. The processing location, the legal basis, the retention clock and the audit trail are contract terms, not promises.
- Processed in the EU
- Never trains a foundation model
- The clinician signs first

EU and India
processing location per market
Signature gate
nothing is filed without a clinician
How IQ handles patient data
Four properties, each checkable against a document rather than a promise.
Processing stays in the EU
The European Union for Slovakia and Czechia. India for the Indian market, under the DPDP Act 2023. A contract term, not a preference.
It never trains a foundation model
Written into the processing agreement. It is the first thing to check with any vendor, including us.
The clinician signs first
IQ drafts and suggests codes. Nothing enters the record without a signature: § 21 in Slovakia, § 12 in Czechia.
Every action is logged and reversible
What was generated, what changed, who signed and when. Immutable, and yours to export.
What a DPO needs before shortlisting IQ
In the order a review asks it. Every row answered.
- Processing location
- European Union for the Slovak and Czech markets; India for the Indian market. Stated per market, never as one global claim.
- Model training
- Patient data is not used to train foundation models. Contractual, not a setting.
- Legal basis
- Art. 9(2)(h) GDPR for health data in the provision of care, with Hilbi acting as processor under Art. 28.
- Transparency toward the patient
- AI Act (EU) 2024/1689 Art. 50(4): machine-generated clinical text is disclosed as such and carries the clinician who signed it.
- Human oversight
- The clinician reviews and signs. IQ does not diagnose and it does not decide; the intended purpose is stated so the MDCG 2019-11 assessment is reproducible.
- Audit trail
- Immutable and exportable: what was generated, what was edited, who signed, when.
- Security of processing
- Art. 32 GDPR controls, managed under an information-security management system currently in ISO/IEC 27001 recertification at group level.
- Retention
- Prompts and drafts for 30 days, signed output under national retention law, audit records for 10 years. The deletion evidence is yours.
- Sub-processors
- Fourteen sub-processors with the purpose and the processing location of each, listed per market.
- Exit
- Monthly term. Your clinical record stays in your system of record; patient-held data exports as an HL7 FHIR R4 bundle.
The instruments this page answers to
Each row is the rule a reviewer will check this page against.
- GDPR (EU) 2016/679: Art. 9(2)(h) legal basis, Art. 28 processing agreement, Art. 32 security of processing, Art. 33 and 34 breach notification.
- AI Act (EU) 2024/1689: Art. 50(4) transparency for machine-generated content; Art. 6(1) classification, addressed on the responsibility page.
- EU MDR 2017/745 with MDCG 2019-11: the intended-purpose statement that keeps the classification assessment reproducible.
- Act 576/2004 Coll. §21 (Slovakia): the clinician's signature before a record entry is final.
- Decree 98/2012 §12 and §7(1) (Czechia): record content and the immutability of the trail.
- DPDP Act 2023 (India): consent, notice and the duty to notify.
- ISO/IEC 27001 with ISO 27799: information-security management applied to health data. Recertification in progress at group level.
What clinicians and their DPOs ask
Does patient data leave the EU?
Is our data used to train models?
Who signs what IQ produces?
Is IQ a medical device?
Will you publish how it is built?
Monthly briefing
The signal, once a month.
What changed in European health data, what we shipped, and what it means for a provider. Nothing else.