Privacy Policy
Afterscan S.R.L.
1. Who we are and what this policy covers
Afterscan S.R.L. (“Afterscan”, “we”, “us”) runs follow-up software for preventive health-scan clinics and occupational-health providers in Sweden. A clinic enrolls its clients after a scan. In the client app, each client uploads their results, confirms the values our software read and answers four family-history questions, and a rules table signed by the clinic’s medical lead lists the tests that are missing. The client books them at a Stockholm lab the clinic works with, the results return to the same record, and the clinic’s own doctor signs a letter to the client’s vårdcentral from the clinic dashboard. We don’t draw blood, run tests, diagnose or sign letters, and nothing our software reads decides which tests are missing.
Registered at Avenida Corrientes 1386, Piso 7, C1043ABN Buenos Aires, Argentina.
We handle personal data in two different situations, and different rules apply to each:
| Whose data | Our role | What applies | |
|---|---|---|---|
| Part A | People who visit this website, ask about the service or write to us | Controller: we decide why and how the data is used | This policy |
| Part B | For each client a clinic enrolls: the scan results uploaded, as a PDF, export or screenshots, and the values confirmed from them; the answers to the four family-history questions; the list of missing tests; bookings and cancellations; the lab results returned to the record; the doctor’s letter and the vårdcentral it is addressed to. Also the row-and-value pairs that come from confirmations, the logins and actions of the clinic’s staff, and the clinic’s contract and invoice records. | Set out in B.1, because it depends on the data | This policy and the data processing agreement we sign with each customer |
If the data processing agreement (“DPA”) and this policy ever disagree about Part B, the DPA wins.
2. Part A: this website and our contact with you
This part covers the personal data we collect for our own purposes: running this website, answering requests, and staying in touch with people who are or might become customers.
A.1 What we collect
What you give us. When you send the form on this site, we collect what you type into it, such as your name, email address, phone number or company, and the fact that you agreed to be contacted. If you email or talk to us, we keep that correspondence and any contact details in it.
What is collected automatically. Our web server records the IP address a request came from, the browser used, the pages requested, the page you came from and the time. These logs exist to keep the site running and secure.
We don’t ask for sensitive data (the “special categories” in Article 9 GDPR) through this website, so please don’t send any through the form.
A.2 Why we use it, and what allows us to
| Why | What | Legal basis (GDPR Art. 6) |
|---|---|---|
| Answering your request and working out whether the service fits | What you sent in the form, our correspondence | Art. 6(1)(b): steps you asked for before a contract |
| Looking after customers, billing and support | Contact details, correspondence | Art. 6(1)(b): carrying out a contract |
| Keeping the site running, secure and free of abuse | Server logs | Art. 6(1)(f): our legitimate interest in running a secure service |
| Contacting you about the service | Email address, company | Art. 6(1)(f): our legitimate interest in business-to-business marketing. You can object at any time |
| Meeting tax, accounting and legal duties | Billing and contract records | Art. 6(1)(c): a legal obligation |
Where we rely on legitimate interest, we have weighed that interest against your rights, and you can ask to see the assessment.
A.3 How long we keep it
- Requests from people who don’t become customers: 12 months from our last contact, then deleted.
- Customer contact and contract records: for the length of the agreement plus ten years, because Argentina’s Civil and Commercial Code has a company keep its accounting records that long.
- Server logs: 30 days.
- A record that you objected or opted out: kept indefinitely, so we can keep respecting it.
A.4 Your rights
If you are in the EEA or the UK, you can ask to see your data, correct it, have it deleted, limit or object to how we use it, get a copy you can take elsewhere, and withdraw consent where we rely on it. Write to [email protected] and we will answer within one month.
You can also complain to a data protection authority. If you are in the EEA, that can be the authority where you live or work.
3. Part B: data inside the service
Two kinds of data pass through Afterscan, and we hold them in different roles. The first is client data: health data about the people a clinic enrolls, which the clinic controls and we process on its written instruction. The second is data about the clinic and the staff who log in, its medical lead, doctors and front desk, together with the clinic’s contract and invoice records. This part covers both, in that order.
B.1 What we handle, and in what role
For everything inside a client’s record we are the clinic’s processor, under a data processing agreement the clinic signs before it enrolls anyone. The clinic is the controller and the caregiver. It collects each client’s explicit consent to the follow-up on a consent screen in the app that carries the clinic’s name and wording, before any upload, and the client can withdraw it there at any time. We act only on the clinic’s instructions in the agreement and the order form. Each lab the clinic books is a caregiver in its own right and controls its own record of the blood draw and the analysis. For the clinic’s account, staff logins, contract and invoices we are the controller.
- The scan results a client uploads. Our software reads the PDF, app export or screenshots into rows of test, value, unit and healthy range, and shows them to the client to confirm. The pages and the confirmed values become the first entry in the client’s record. The clinic’s doctors see the original pages next to the confirmed values. No lab does.
- The four family-history answers. Whether a parent or sibling had a heart attack or stroke before 55 for a man or 65 for a woman, the client’s age, whether high cholesterol runs in the family, and whether Lp(a) has ever been measured. The rules table reads them, and the clinic’s doctors see them. The app asks nothing else about relatives.
- The missing tests and the booking. The tests the rules table names, the lab and time the client chose, and any cancellation. The lab gets the client’s name, date of birth, contact details and the tests the clinic ordered, and nothing from the scan. We take no payment from a client.
- Lab results and the letter. The results the lab sends back go into the record, both as the lab’s document and as confirmed values. The letter holds the values the clinic’s doctor chose to mention and the name of the client’s vårdcentral. The client gets it as a signed PDF, and it goes to the vårdcentral only if the client asks.
- The clinic dashboard. Which enrolled clients have open gaps, which tests are booked, which results are back and which letters wait for a signature. Only the clinic’s own staff see it, each with a personal login and one of three roles: medical lead, doctor or front desk. The front desk sees names and statuses, never values.
- Clinic, staff and contract records. The clinic’s legal name, organisation number and registered address, the name, work email and role of each staff member with a login, the license number of each doctor who signs, the order form and our invoices. We use them to run and invoice the contract.
We never receive a blood sample, and we have no account in any lab’s analysis system. Results reach the record as documents the lab sends back.
We have no login to the clinic’s journal, results or booking systems. A client’s record starts with what the client uploads, so a clinic goes live without an integration.
An employer that pays an occupational-health provider for health checks never sees a record, a list or a letter, and has no login.
A doctor sees only the records of the clinic they sign for, and only inside the service, never as an export.
B.2 What we do with it
Everything runs in Stockholm. Client records, the dashboard, bookings and the clinic’s account run on cloud infrastructure in Stockholm, Sweden. The models that read uploads, and their fine-tuning, run on cloud GPU capacity we control in Stockholm. We have no second location, and no page of a result leaves Sweden.
No hosted model provider. No part of a result, a screenshot or a letter is sent to a third-party model API. We run the reading models ourselves. The only third parties involved are the cloud provider named on our subprocessor list, whose infrastructure in Stockholm the service runs on, the provider that sends enrollment links by text message and email, and the postal service when a client asks for a letter to be posted.
The software reads, the rules decide, the clinic’s doctor signs. A value is never used until the client confirms it, and a value read with confidence below 0.9 is left blank for the client to type. Which tests are missing is decided by a fixed rules table the clinic’s medical lead signed, not by a model. Our software fills a letter template with the confirmed values; a doctor the clinic named edits it and signs it under their own license.
The lab sees the order, not the scan. A booking gives the lab the client’s identity, contact details and the tests the clinic ordered. The scan values, the family-history answers and the list of missing tests stay in the record. The lab doesn’t receive them and doesn’t need them to take and analyze the sample.
Confirmed rows are stripped before we keep them. When a client or a clinic’s doctor confirms a value our software read, we keep a crop of that one result row together with the confirmed value. The page header, the client’s name and everything outside the row are removed. The clinic authorizes this in the processing agreement. The pairs are used only to fine-tune our own reading models, are never given to a lab, a clinic or anyone else, and are deleted with the record on request.
B.3 AI models: where they run and what they learn from
Where models run. All models run on cloud GPU capacity we control in Stockholm, Sweden. One model finds the result rows in an uploaded scan result, screenshot or lab report. Another reads each row into test, value, unit and healthy range, with a confidence score. No part of any result, screenshot, answer or letter is sent to a third-party model API, and there is no hosted model provider on our subprocessor list. The models are fine-tuned on the same capacity in Stockholm. From Q1 2027 the reader is one fine-tuned open-weight vision-language model, self-hosted on that capacity. From Q3 2027 the evening and weekend bursts run on GPU capacity reserved in advance in Stockholm.
Training. We don’t train any model on a client’s record, answers, lab results or letters, and no third party receives them to train on. There is one narrow exception, which the clinic authorizes in the processing agreement. When a client or a clinic’s doctor confirms a value our software read, we keep a crop of that single result row together with the confirmed value, with the page header, the client’s name and everything outside the row removed. Those pairs are used only to fine-tune our own reading models. They are pooled across clinics, because a lab’s layout is not personal to anyone. They hold no name and no history, and they are deleted with the record on request.
Where a person decides. The model reads and people decide, twice. A value read with confidence below 0.9 is left blank for the client to type. A value above it is shown to the client and used only once the client confirms it. Which tests are missing is decided by a fixed rules table the clinic’s medical lead signed, and the model plays no part in that. The letter is edited and signed by a doctor the clinic named, who sees the confirmed values and the original pages. No booking, list or letter is produced by an automated decision, and this service takes no decision with a legal or similarly significant effect on any person.
B.4 Where the data is kept
All processing and storage is on cloud infrastructure in Stockholm, Sweden. The reading models and their fine-tuning run on cloud GPU capacity we control in Stockholm.
No result, screenshot, answer or letter is sent to any hosted model API. Nobody outside Afterscan runs a model on it.
The clinic’s own journal and each lab’s care record stay where the clinic and the lab keep them, under their own duties as caregivers in Sweden. A record in Afterscan is a copy of neither.
The suppliers that handle data in the service are named on our subprocessor list, which comes with the data processing agreement and which we send to anyone who asks: write to [email protected].
B.5 How long we keep it, and what deleting can’t remove
A client’s record, including uploads, confirmed values, answers, the list of missing tests, lab results and letters: for as long as the clinic’s contract runs, unless the clinic deletes it sooner or the client withdraws consent, and in any case no longer than three years after the client’s last upload or booking.
At the end of the contract the clinic receives every record in open formats, and we delete our copy ninety days after the clinic confirms the export, unless the processing agreement sets a different period.
Row-and-value pairs: until the record they came from is deleted, and deleted with it on request.
A doctor’s letter: in the record for as long as the record exists. The clinic keeps its own copy in its journal under its duties as a caregiver.
The access log of which staff login opened which record: for the length of the contract, then exported to the clinic with the records.
Contract, account and invoice records: for the length of the contract and ten years after, because Argentina’s Civil and Commercial Code has a company keep its accounting records that long.
B.6 Requests from people whose data is in the service
A client’s request about their record, whether access, correction, deletion, objection or a portable copy, goes to the clinic, which controls it. In the app the client can also read and download the record at any time, and withdraw consent, which stops the follow-up and deletes the record. When a clinic forwards a request, we help it within five working days and act only on its instruction. A client who writes to us directly gets the clinic’s contact details within five working days. A request about a lab’s care record goes to that lab. For the staff contact data we control, we answer directly on access, correction, deletion and objection within thirty days.
For everyone
4. Moving data between countries
Afterscan S.R.L. is a company in Argentina, outside the EEA, and handles personal data under Argentina’s Personal Data Protection Law 25.326 and, where it applies, the GDPR. Section B.4 says where the data in the service is kept. When personal data from the EEA or the UK reaches us, for example because someone there writes to us or a customer there uses the service, it is protected by the European Commission’s adequacy decision for Argentina, or by its Standard Contractual Clauses, and the technical measures described in our security documentation. You can ask us for a copy. In Argentina you can complain to the Agencia de Acceso a la Información Pública.
EU representative (Article 27 GDPR). Write to [email protected] with “EU representative” in the subject line and we will send you our representative’s details.
5. Security
We protect data in line with the risk. That includes encryption in transit and at rest, access limited to the people and systems that need it, each customer’s data kept separate from every other’s, and a log of every access to production systems.
If a personal data breach affects you, we tell you without undue delay, and at the latest within 36 hours of finding out, with the information you need to meet your own reporting duties.
6. Children
The service is sold to businesses and is not meant for children. We don’t knowingly collect personal data from anyone under 16.
7. Changes to this policy
We may update this policy. If a change matters, we email customers at least 30 days before it takes effect. The version number and date at the top of this page change every time.
8. Contact
Privacy questions and anything else: [email protected]
By post: Afterscan S.R.L., Avenida Corrientes 1386, Piso 7, C1043ABN Buenos Aires, Argentina