Privacy Policy.
How Kodia handles personal data under the Swiss Federal Act on Data Protection (FADP; DSG in German).
Last updated: 6 August 2026.
1. Who we are
Kodia is operated by MS2 Partners Sàrl (CHE-240.674.424), Route de Lausanne 15, 1180 Rolle, Vaud, Switzerland (“Kodia”, “we”, “us”). Contact: contact@kodia.ch.
This Privacy Policy explains how we process personal data in connection with the Kodia website and Kodia Chat. Kodia is a Swiss service and is primarily governed by the Swiss Federal Act on Data Protection (FADP; DSG in German).
2. Language
This Privacy Policy is published in French, English, German, and Italian. The French version is the authoritative text and prevails in case of conflict or divergence between versions.
3. Roles: your practice and Kodia
For account, billing, and service operation data, Kodia acts as the data controller.
Kodia does not require or intend to receive information that identifies a patient. Before submitting clinical text, you must remove names, dates of birth, addresses, identification numbers, and other identifying information. Kodia does not need patient identity to suggest codes.
Removing direct identifiers does not always make a note legally anonymous, as a patient may remain identifiable from context. If submitted content nevertheless contains personal data, the relevant healthcare organization remains the controller. Where a billing service processes data on behalf of that organization, it acts as processor and Kodia acts as sub-processor. Kodia processes that content solely to provide the service and in accordance with the controller’s instructions.
4. Kodia Audit and Kodia Review
Kodia Audit and Kodia Review are engagements with healthcare organizations. For those services the client organization is the controller and Kodia acts solely as processor. Scope, security measures, sub-processors, and retention for client-provided clinical and billing data are governed by the data processing agreement signed with each client. This Privacy Policy continues to apply to account, contact, billing and security data for which Kodia acts as controller.
5. What we do not store by default
The service is designed to minimise storage:
- We do not retain clinical inputs on our servers by default. Inputs may be stored if you enable chat history sync (section 7) or create a shared session (section 8).
- We do not store embeddings or vector representations derived from your input.
- By default, your questions and conversations are retained only in your browser’s local storage. Each question is transmitted temporarily to Kodia and Amazon Bedrock as necessary to process the request, but is not retained on our servers unless you enable chat history sync (section 7) or create a shared session (section 8).
- We do not sell personal data, and we do not use customer queries, clinical documents, or billing data to train artificial intelligence models.
6. What we may store
- Account data — e-mail address, hashed password, name (optional), language preference, terms acceptance timestamp, marketing e-mail preference, and consent preferences.
- Practice and team data — practice or organization identifier, practice name, default canton (optional), team membership and invitation status, and the association between users and practices.
- Provider data — provider display name, GLN/ZSR if provided, and qualification or intrinsic-value information used to filter suggestions.
- Chat history — only if you enable chat history sync. See section 7.
- Shared sessions — if you share a chat session, the conversation content and a share token are stored to enable access via the link. See section 8.
- Results data — suggested codes and ambulatory forfait outputs with related metadata, such as timestamps and selected provider.
- Security and audit logs — login events, system audit logs, and technical metadata required to operate and protect the service, including IP address, browser and device information, request timestamps, and error information.
- Billing data — Stripe customer identifiers, purchase history, and invoice or receipt identifiers.
- Correspondence — messages you send us by e-mail or through support channels.
7. Chat history sync — optional opt-in
Chat history sync lets you reach your conversation history from several devices. It is disabled by default and requires your explicit opt-in consent.
Default behaviour, without consent
- Your questions and conversations are retained only in your browser’s local storage.
- Each question is transmitted temporarily to Kodia and Amazon Bedrock as necessary to process the request and return a response. Nothing is retained on our servers beyond that.
- If you clear your browser data or switch devices, your local chat history is lost.
If you enable chat history sync
- You enable the feature in the Settings section of the application.
- Your questions, the responses, and related metadata such as timestamps and referenced codes are stored on our servers in Switzerland.
- We record the date and time you gave consent, for audit purposes.
Revoking consent and deleting history
- You may revoke consent at any time in Settings. All stored chat sessions are then promptly removed from our active systems.
- Revoking consent does not affect your local browser storage.
- Even with consent enabled, you may delete individual sessions or your entire history at any time.
- Encrypted backup copies may persist for up to 90 days before being overwritten. They are not accessible through the service or used for ordinary processing. If a backup is restored, applicable deletion requests are re-applied.
8. Shared chat sessions
You may share a chat session by generating a share link. The conversation content is then stored on our servers and accessible to anyone holding the link, without authentication. The link can be forwarded by any recipient.
Do not share sessions containing identifying or confidential patient information. You may revoke a share link at any time, after which the session is no longer publicly accessible, but revocation cannot remove copies, screenshots, or exports already made by viewers.
Shared sessions do not reveal your name, e-mail, or account information to viewers. Sharing is independent of chat history sync and does not require it to be enabled.
9. Why we process data
We process data to provide and operate the service, including authentication, credit usage, and display and export of results; to secure the service, including fraud prevention, abuse monitoring, and audit trail; to provide support and answer enquiries; and to manage billing, receipts, and accounting.
10. Where processing happens
The Kodia application and database are hosted in Switzerland by Infomaniak. Coding suggestions and Chat queries are submitted to Amazon Bedrock through the AWS Europe (Zurich) endpoint using an EU geographic inference profile. Depending on available capacity, artificial intelligence inference may be processed in Switzerland or in AWS regions located in Germany, Sweden, Italy, Spain, Ireland, or France.
Model invocation logging is disabled in our configuration. Amazon Bedrock does not use customer data to train its models and does not retain prompts or outputs in that configuration.
Data stored in Switzerland includes account data, suggested codes, audit logs, billing records, and, if you enable chat history sync, your chat conversations.
11. Service providers, recipients and sub-processors
- Infomaniak (Switzerland) — application and database hosting. Data remains in Switzerland.
- Amazon Web Services — artificial intelligence inference through Amazon Bedrock. Requests are submitted through the AWS Europe (Zurich) endpoint using an EU geographic inference profile. Depending on available capacity, inference may be processed in Switzerland or in AWS regions located in Germany, Sweden, Italy, Spain, Ireland, or France.
- Stripe group companies, principally Stripe Payments Europe, Limited (Ireland) — payment processing, receipts, invoices, fraud prevention, and compliance with financial regulations. Stripe may act as a processor or as an independent controller depending on the processing activity. Data may be processed in Ireland and other countries, including the United States. Stripe generally retains payment-related personal data for five years or longer after the end of the customer relationship or the last transaction, depending on applicable legal, regulatory, fraud-prevention, and accounting requirements.
- Resend, operated by Plus Five Five, Inc. (United States) — delivery of verification and transactional e-mails. Resend processes recipient e-mail addresses, message content, and delivery metadata in the United States. E-mail data is generally retained for 30 days under standard plans. Kodia does not use Resend to transmit clinical or patient information.
Transfers to the European Union rely on the European Economic Area being recognised by the Swiss Federal Council as providing adequate protection. Transfers to the United States rely on the Swiss–U.S. Data Privacy Framework where the relevant recipient is certified. Otherwise, they rely on recognised Standard Contractual Clauses adapted to Swiss data protection law. Stripe is certified under the Swiss–U.S. Data Privacy Framework; transfers to Resend rely on Standard Contractual Clauses adapted for Switzerland. Data may also be disclosed where required by law or by a competent authority.
12. Data retention
We keep data only as long as necessary for the purposes described above. Typical retention periods:
- Account and practice data — until account deletion, unless retention is required by law.
- Chat history, if consent given — until you delete it, revoke consent, or delete your account. Removal from active systems is prompt; encrypted backups are overwritten within 90 days.
- Security and audit logs — generally up to 24 months, then deleted or anonymised.
- Billing records — generally 10 years, to meet accounting and tax obligations.
- Backups — generally 30 to 90 days.
These retention periods describe data retained by Kodia. Service providers may retain data for different periods where required by their own legal, regulatory, security, or contractual obligations, as described in section 11 and in their applicable privacy terms.
13. Your rights
Within the limits provided by the FADP, you may request information about whether we process your personal data, and request correction or deletion where applicable. Contact contact@kodia.ch.
You can also manage data directly in the application: enable or disable chat history sync in Settings → Data; delete individual chat sessions or your entire history; revoke consent, which removes all stored chat data from our active systems (see section 7); revoke shared session links, which removes public access immediately; and delete your account.
When you delete your account, your account, practice, and chat data are deleted or anonymised. Some records are retained where the law or the security of the service requires it, in particular billing records, security and audit logs, and encrypted backups, according to the periods in section 12.
If you use Kodia through a practice or billing service, requests related to patient-related content may need to be handled by that organization as controller.
You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) in Bern.
14. Security and breach notification
We apply technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit, access controls, and audit logging.
Where Kodia acts as controller, we notify the FDPIC of a data security breach that is likely to result in a high risk to the persons concerned, and inform those persons where required. Where Kodia acts as processor, we inform the relevant controller promptly and assist it in meeting its own obligations.
15. Cookies and local storage
We do not use third-party advertising cookies and we do not use analytics by default. We use only essential technical storage required for login, session, and preferences such as language.
The technical logs described in section 6, including IP address and browser information, are recorded to operate and secure the service. They are not used to analyse your behaviour, build profiles, or measure audience.
By default, your questions and conversations are retained only in your browser’s local storage. Each question is transmitted temporarily to Kodia and Amazon Bedrock as necessary to process the request, but is not retained on our servers unless you enable chat history sync or create a shared session. Clearing your browser data removes locally stored chat history.
16. Automated assistance
Kodia provides artificial intelligence-assisted coding suggestions. Kodia does not make fully automated decisions producing legal effects. Human review by the practice is required before billing.
17. Intended users
Kodia is a professional tool intended for healthcare providers, practice staff, and billing services. It is not intended for use by patients or by persons under 16.
18. Changes
We may update this policy as the service or the law evolves. The current version is always published on this page.
19. Contact
MS2 Partners Sàrl (CHE-240.674.424)
Route de Lausanne 15, 1180 Rolle, Vaud, Switzerland
E-mail: contact@kodia.ch