
SHOMA® AI
Health API
Last updated: August 5, 2026
This Privacy Policy applies to the SHOMA AI Health API service operated by Labelscoin Dr. Serena Spada, Via Massagno 24, 6900 Lugano, Switzerland ("we", "us", "our").
This service is designed exclusively for professional use by authorised staff of hospitals and clinics. Patients have no access to the system.
We process clinical documents only for the duration of the analysis request. - Documents and any associated data are used solely to generate a temporary report. - Immediately after the report is generated, all data is cancelled and permanently deleted. - We do not store, retain, log or use any patient data, personal data or Protected Health Information (PHI) after the session ends. - We do not train any models on patient data.
Our system is built on a strict zero-retention architecture: - No patient data is stored on our servers. - No backups of clinical content are kept. - Once the temporary report is delivered to the authorised user, the source data and the report content are permanently deleted from our systems.
We maintain fully anonymised technical activity logs for security and operational purposes only. These logs contain no patient data, no personal data and no identifiable information. They are automatically deleted after a maximum of six months.
Where the GDPR applies, processing is based on: - Performance of a contract with the hospital/clinic (Art. 6(1)(b) GDPR), and - Our legitimate interest in providing a secure administrative tool (Art. 6(1)(f) GDPR), balanced against the rights of data subjects through our zero-retention design.
We do not share any patient or clinical data with third parties. Data never leaves the processing environment except as the temporary report returned to the authorised user.
If data is processed outside the EU/EEA, appropriate safeguards (including Standard Contractual Clauses) are in place. Due to our zero-retention design, clinical data is not retained in any location.
Because we do not store patient data, most data-subject rights (access, erasure, etc.) are fulfilled by our automatic permanent deletion. Hospitals and clinics remain the data controllers for any data they choose to save locally after receiving the temporary report.
For privacy questions: support@shoma-ai.com