Information under Articles 13 and 14 GDPR and the Austrian Data Protection Act. This policy aligns exactly with what our code does. Last updated: 28 May 2026.
Knightify FlexCo, Rauchgasse 28 Top 2, 1120 Vienna, Austria.
Company register: FN 666564 t, Commercial Court Vienna.
Privacy contact: [email protected].
We are not required to designate a Data Protection Officer (Article 37(1) GDPR does not apply to our scope at current scale). You can reach us for any data-protection matter at the address above.
Full provider details in the Imprint.
This policy applies to the website at continuumcare.app, all related applications, our mobile API, and the transactional emails we send you in relation to your account. It does not apply to external sites we link to.
When you load a page, our hosting provider automatically processes your IP address, the date and time, the HTTP method, the requested URL, the referrer header, and your user-agent string. These are technically required to deliver the page and to detect abuse. Legal basis: Article 6(1)(f) GDPR. Retention: 30 days in server logs, then automatic deletion.
We self-host all fonts and CSS. No external font request goes to Google or Adobe. There are no tracking pixels, web beacons, or advertising IDs.
You can create a brief without registering. For this, we process:
The legal basis for processing your health data is your explicit consent under Article 9(2)(a) GDPR. You give consent by ticking the box before upload. You may withdraw consent at any time with effect for the future by cancelling the upload flow or deleting your account.
When you register, we process:
Legal basis: Article 6(1)(b) GDPR (contract performance), and for security logs Article 6(1)(f) GDPR.
When you save a brief to your account, we keep the structured summary (brief_data) and the medical timeline (timeline_data) encrypted at rest in our database. The original file (PDF, JPG, PNG) is deleted immediately after the AI pipeline finishes and is never stored. We additionally store patient initials, language, the number of source documents, and a flag for low-confidence output.
Legal bases: Article 9(2)(a) GDPR (explicit consent for health data) and Article 6(1)(b) GDPR (contract performance).
You enter the reason for the visit, date, symptoms, current medications, past conditions, and notes about recent reports. We store these inputs (input_data) and the AI response containing pre-visit checklist and questions (output_data) encrypted in the visit_preps table. Both fields are health data under Article 9 GDPR. Legal bases: Article 9(2)(a) and Article 6(1)(b) GDPR.
Optionally you create a share link for an accompanying person (see 3.10).
You paste the text of a medical report (up to 12,000 characters). We store the pasted text (source_text) and the explanation (output_data) encrypted in the document_simplifications table. Both fields are health data. Legal bases as above.
You record what the clinician said, any new findings, and follow-up items. We store your inputs (input_data), the structured reflection (output_data), the clinician summary (clinician_summary), and the visit date (visited_at) encrypted in the visit_reflections table. You can mark follow-ups as done or open.
You supply reason, symptoms, medications, and past conditions. We produce four to six calm, doctor-friendly follow-up questions. By default we do not store the request independently; the questions end up in an associated Visit Prep or Brief if you save it.
The timeline is a view on your dashboard. It aggregates events from your saved briefs. No additional records are created. All source information is already encrypted in brief_data and timeline_data.
You can create a read-only share link for a Visit Prep. We generate a random token and an expiry (seven days). Anyone with the link can read the Visit Prep but cannot modify it. You can revoke the link at any time, effective immediately. The content itself stays encrypted.
Please share the link only with people you trust. The link will be visible in the recipient's browser history and server logs. For sensitive handovers we recommend caregiver access (3.11), which requires sign-in.
You can grant a trusted person access to a single brief. For this we process:
You may revoke access at any time. On revocation the caregiver relationship is effective immediately, even if the brief is still open in the caregiver's browser (the server re-checks on every request).
In the "Account" area you can download a complete copy of your data as a JSON file or irreversibly delete your account. The export contains your profile, all briefs (including soft-deleted), Visit Preps, reflections, document simplifications, caregiver records, caregiver invitations, consent log, and AI-request metadata. A deletion removes all these records immediately and irreversibly.
We currently use only strictly necessary cookies: a session cookie that signs you in, a CSRF cookie that protects against cross-site request forgery, and a cookie for your selected language. These are permitted without consent under § 165(3) TKG 2021 (Austria) and Article 5(3) of the ePrivacy Directive because they are strictly necessary for the service to function.
On your first visit we still show a cookie banner with four categories (strictly necessary, preferences, analytics, marketing). The three optional categories are off by default. They activate only when you explicitly opt in, and we load the associated scripts only then. At present no optional script is loaded, so your choice has no visible effect today. Your choice is stored in a first-party cookie "continuum_consent" (12-month duration) and can be changed or withdrawn at any time via "Cookie settings" in the footer.
We additionally store your theme choice (system, light, dark) in your browser's localStorage. This value never leaves your device and is not transmitted to our servers.
We log each granting or change of your cookie consent in the consent_logs table together with an HMAC hash of your IP address (for abuse defence, not for re-identification) and your user agent. Legal basis: Article 6(1)(c) GDPR (accountability obligation).
All medical content (diagnoses, symptoms, medications, findings, lab values, treatments, history, reflections) is "special category personal data" under Article 9(1) GDPR. We process this data only on the basis of your explicit consent under Article 9(2)(a) GDPR. You give consent:
You may withdraw consent at any time with effect for the future by deleting the relevant data record or your account, or by emailing us at [email protected]. The lawfulness of processing before withdrawal is not affected.
We disclose your data to third parties only to the extent necessary to operate the service. Each recipient is a processor under Article 28 GDPR.
No other recipients are involved. We comply with authority requests for disclosure only to the extent required by Austrian or directly applicable EU law.
Full technical details on the Security page.
We respond to requests regarding your rights within 30 days of receipt, extendable in complex cases to a total of three months (Article 12(3) GDPR).
Continuum performs no automated individual decision within the meaning of Article 22 GDPR. AI processing produces a descriptive summary of your documents, a pre-visit checklist, a term explanation, or a list of questions. It makes no decision about you, no diagnosis, no treatment instruction, and replaces no medical advice. When the model is uncertain, we mark the output as low confidence. You stay in full control at every step.
Processing of health data with the help of an AI processor in a third country meets several criteria of the Austrian DPA's mandatory-DPIA list (BGBl. II No 278/2018 as amended). We have carried out and documented a Data Protection Impact Assessment under Article 35 GDPR. We provide a summary of the findings on request.
In case of a personal-data breach that is likely to result in a risk to your rights and freedoms, we notify the Austrian Data Protection Authority within 72 hours of becoming aware (Article 33 GDPR) and notify you directly without undue delay if there is a high risk (Article 34 GDPR).
Continuum is not directed at persons under 16. Independent grant of data-protection consent is possible from age 14 under Article 8 GDPR and § 4(4) Austrian DSG, provided the necessary discernment is given. For caution, we require a minimum age of 16. When processing data of a minor in your care, you must act as legal representative or with their consent.
In addition to the GDPR we observe the Austrian Data Protection Act (DSG, BGBl. I No 165/1999 as amended), the Austrian Telecommunications Act 2021 (TKG 2021, in particular § 165 on cookies), and the Austrian E-Commerce Act (ECG, § 5 on provider identification). Continuum is not connected to ELGA (the Austrian electronic health record) and is not a substitute for ELGA or any other state-provided health infrastructure.
We update this policy when our processing, the underlying technology, or applicable law changes. Material changes are announced at least 30 days before they take effect, by email to account holders and by a notice in the account area. The current version is always available on this page with the date of its last update.
Privacy: [email protected].
Security: [email protected].
General: [email protected].