Omi Health — Legal
Last updated: 11 August 2026
Provider: Omi Health B.V., Eindhoven, Netherlands
Australian entity: Omi Health Pty Ltd, Perth, Australia
Contacts: [email protected] · [email protected] · [email protected]
Which documents apply
| Product or surface | Documents |
|---|---|
| Public websites at omi.health and omiscribe.com | Website Privacy Policy |
| Speech-to-Text API and Playground | API Terms, API Privacy Note, and DPA; the BAA also applies after execution for HIPAA-regulated use |
| Omi Scribe Cloud (Managed) | Cloud Terms, Cloud Privacy Notice, Sub-processors, and any DPA or BAA executed with the Customer |
| Omi Scribe for Mac | Mac EULA and Mac Privacy Policy |
| Customer-managed or self-hosted deployment | The separately agreed deployment terms and any DPA or BAA applicable to that deployment |
This table is a guide. A signed order form or negotiated agreement takes precedence where it says otherwise.
Website (omi.health, omiscribe.com)
Omi Scribe Cloud (Managed)
The cloud Service is delivered as a single deployment in Azure Sweden Central (EU) under GDPR. Customers requiring local data residency use Omi Scribe for Mac (on‑device, in beta) or customer‑managed self‑hosted deployment in the Customer's own Azure / AWS / GCP tenant.
Region-specific addenda
- UK Privacy Addendum — ICO, IDTA, UK GDPR, NHS DSPT support
- AU / NZ Privacy Addendum — APPs, OAIC, My Health Record, NDB scheme; NZ IPPs and Office of the Privacy Commissioner
- US Privacy Addendum — CCPA/CPRA and other state laws; HIPAA framing
- Dutch healthcare requirements — contact [email protected] to discuss NEN 7510 and BoZ requirements. No standard public addendum is published today.
HIPAA (US)
A Business Associate Agreement (BAA) is required for HIPAA-regulated workflows. For the Speech-to-Text API, the BAA is published and can be signed self-serve in the console — no sales contact required. For Omi Scribe Cloud, contact [email protected].
Dutch healthcare
Dutch healthcare organisations (zorginstellingen) can contact [email protected] to discuss NEN 7510 and BoZ contracting requirements. These are handled case by case today.
Speech-to-Text API (api.omi.health)
The developer API is a generally available, paid product, processed in the EU (AWS eu-central-1). Real patient audio is supported from the first request — the Data Processing Agreement is accepted at signup and a Business Associate Agreement can be signed self-serve in the console, on every tier including the free one.
- Data Processing Agreement (DPA) — GDPR Article 28, click-through at signup
- Business Associate Agreement (BAA) — HIPAA, self-serve in the console
- Sub-processors
Result artifacts are retained only until your configured expiry — default 24 hours, configurable from 1 to 72 hours. Owner-scoped job metadata may remain for up to 72 hours so expired jobs return a stable response. Audio is deleted when transcription completes. Jobs delivered by webhook carry an effective 9-hour minimum so a final delivery retry can still be picked up. Customer content is never used to train models.
> Note on which documents apply to you. The retention periods and the Azure region described under Omi Scribe Cloud above govern the Scribe application, not the API. API customers are governed by the DPA and BAA linked in this section.
- API & Playground Terms of Use — accepted in the console at signup
- Privacy Note
Playground
The public STT Playground is for evaluation. Playground audio is deleted immediately after transcription.
Omi Scribe for Mac (Offline)
The Mac app processes data on-device only and does not require a DPA, BAA, or region-specific addendum in most jurisdictions.
Security and compliance
- Report security issues: [email protected]
- Privacy inquiries: [email protected]
Enterprise security pack (available under NDA): DPA, DPIA, Records of Processing (ROPA), Incident Response Plan, and internal security policies (Information Security, Access Control, Data Classification, Azure compliance inheritance, technical reality summary).
Production readiness evidence (May 2026): Azure Monitor alert rules, Postgres PITR drills with in-VNet smoke (RTO 7-12 min observed), secret rotation drills from regional Dev VMs, and 8-domain compliance evidence pack (Identity, Network, Data Protection, Audit, Application Security, Resilience, Supply Chain, Operational Controls). Available under NDA.