← Responda

Privacy Policy

Last updated August 29, 2026

This describes what Responda actually stores, where it physically sits, and every third party that touches it. It is written to be checkable rather than reassuring.

Who this covers

Responda is used by EMS agencies. Two different sets of people appear in the system: clinicians and administrators who hold accounts, and patients whose care is documented. Patients do not hold accounts and do not interact with the software.

For patient information, the agency is the covered entity and Responda is its business associate. We process patient data on the agency's instructions, under a Business Associate Agreement. Patients seeking their own records should contact the agency that treated them — we cannot release records directly.

What we store

From clinicians: name, work email, agency, role, and an authentication identifier from your sign-in provider. We record which charts you opened, edited, signed, and which AI suggestions you accepted, rejected, or edited.

From calls: the audio you record, the transcript produced from it, the structured chart values, and the narrative. This includes protected health information — patient name, age, complaint, vitals, medications, and disposition — because that is what a patient care report is.

We do not sell data, do not use patient data for advertising, and do not use it to train machine learning models.

Where it physically is

All processing is on Microsoft Azure in the United States, under a Business Associate Agreement with Microsoft:

  • Charts and accounts — Azure Database for PostgreSQL, North Central US. Encrypted at rest and in transit.
  • The application — Azure App Service, North Central US.
  • Transcription and extraction — Azure OpenAI, East US 2.

Access to the database is restricted by network rules to the application's own addresses and named administrators. Charts are isolated per agency at the database level.

Third parties who touch data

The complete list. There are no advertising, analytics, or data-broker recipients.

  • Microsoft Azure — hosting, database, and AI processing. Business Associate Agreement in place.
  • Google — sign-in only. Google receives an authentication request and returns your identity. No chart content is sent to Google.

Azure OpenAI abuse monitoring

This deserves stating plainly rather than burying. By default, Azure OpenAI retains prompts and generated output for up to 30 days so Microsoft can review them for platform abuse. For Responda, those prompts contain transcript text, which contains patient information.

That retention is covered by our Business Associate Agreement with Microsoft, and the data stays in the same geography. It nonetheless means a limited number of authorized Microsoft personnel could review content that includes PHI.

We have applied to Microsoft to disable abuse monitoring for this workload. Until that is approved, the behavior above is accurate. We will update this section, with the date, when it changes.

How long we keep things

Charts are retained for as long as the agency's agreement and its own record retention obligations require — typically set by state law, often measured in years. Responda does not decide an agency's retention schedule.

Charts are voided rather than deleted. A voided chart and its audit trail remain, marked void with the actor and reason, because a patient care report is a legal record and silent deletion would destroy the trail that proves what happened.

Audit trail

We record who created, edited, signed, or voided a chart, and which AI suggestions were accepted, rejected, or edited, with timestamps.

To be accurate about the current limit: reads, prints, and exports are not yet fully audited. An agency needing a complete access log for every view should ask us about status before relying on it.

Security

Encryption in transit and at rest, per-agency data isolation enforced in the database, network-restricted database access, and role-based permissions. Optional multi-factor authentication is available and an agency should ask us to enable it.

Responda has not completed a SOC 2 audit and does not hold a HIPAA certification — no such certification exists. We are happy to walk any agency through our actual controls.

Breach notification

If we discover unauthorized access to protected health information, we will notify the affected agency without unreasonable delay and within the timeframe required by our Business Associate Agreement and applicable law, with what we know about scope and cause. The agency handles notification to affected individuals as the covered entity.

Your choices

Clinicians may request a copy or correction of their own account information at hello@responda.us. Requests about patient records must go through the treating agency, which holds the legal relationship with the patient.

Changes

When this policy changes materially we will update the date above and notify agency administrators. This page is a factual description of a running system; when the system changes, the page changes with it.

Contact

hello@responda.us

Questions about this document: hello@responda.us