Omi Health — Legal
Last updated: 25 August 2026
Provider: Omi Health B.V., Eindhoven, Netherlands
Australian entity: Omi Health Pty Ltd, Perth, Australia
Contacts: [email protected] · [email protected] · [email protected]
Which documents apply
| Product or surface | Documents |
|---|---|
| Public websites at omi.health and omiscribe.com | Website Privacy Policy |
| Speech-to-Text API and Playground | API Terms, API Privacy Note, and DPA; the BAA also applies after execution for HIPAA-regulated use |
| Omi Scribe Cloud and Omi Scribe for Mac — discontinued | Products retired August 2026; their legal documents are no longer published. Records of past processing are available to affected customers via [email protected] |
| Customer-managed or self-hosted deployment | The separately agreed deployment terms and any DPA or BAA applicable to that deployment |
This table is a guide. A signed order form or negotiated agreement takes precedence where it says otherwise.
Website (omi.health, omiscribe.com)
Speech-to-Text API (api.omi.health)
The developer API is a generally available, paid product, processed in the EU (AWS eu-central-1). Real patient audio is supported from the first request — the Data Processing Agreement is accepted at signup and a Business Associate Agreement can be signed self-serve in the console, on every tier including the free one.
- Data Processing Agreement (DPA) — GDPR Article 28, click-through at signup
- Business Associate Agreement (BAA) — HIPAA, self-serve in the console
- Sub-processors
Result artifacts are retained only until your configured expiry — default 24 hours, configurable from 1 to 72 hours. Owner-scoped job metadata may remain for up to 72 hours; expiry tombstones may remain up to 24 hours after result expiry (at most 96 hours after submission) so expired jobs return a stable response. Audio is deleted when transcription completes. Jobs delivered by webhook carry an effective 9-hour minimum so a final delivery retry can still be picked up. Customer content is never used to train models.
HIPAA (US)
A Business Associate Agreement (BAA) is required for HIPAA-regulated workflows. The BAA is published and can be signed self-serve in the console — no sales contact required.
Dutch healthcare
Dutch healthcare organisations (zorginstellingen) can contact [email protected] to discuss NEN 7510 and BoZ contracting requirements. These are handled case by case today.
- API & Playground Terms of Use — accepted in the console at signup
- Privacy Note
Playground
The public STT Playground is for evaluation. Playground audio is deleted immediately after transcription.
Security and compliance
- Report security issues: [email protected]
- Privacy inquiries: [email protected]
Enterprise security pack (available under NDA): DPA, DPIA, Records of Processing (ROPA), Incident Response Plan, and internal security policies (Information Security, Access Control, Data Classification, technical reality summary), aligned to the AWS eu-central-1 deployment.