Transparência da IA
Em vigor desde:
Documento apresentado em inglês
Este documento não está disponível no idioma em que navega, pelo que apresentamos a versão inglesa. É o texto atual, em vigor desde a data indicada acima. A versão polaca continua a ser a juridicamente vinculativa.
Why this document exists
Regulation (EU) 2024/1689 on artificial intelligence (the AI Act) requires, in Article 50, that people are told plainly when they are talking to a machine and when they are reading machine-generated content. That obligation has applied since 2 August 2026.
This document sets out where artificial intelligence sits in Medova, what exactly it does, who oversees it and what it does not do. It also names the features that look like AI but are not, because that misunderstanding is just as misleading.
No AI system in Medova makes a diagnosis, qualifies anyone for a vaccination or decides anything about your treatment. Every output is informational or administrative.
Register of AI systems whose output users can see
This register mirrors the internal AI systems register maintained by Medova and reviewed quarterly.
| System | What it does | Model and vendor | How it is labelled | Human oversight |
|---|---|---|---|---|
| Country health summaries | Describes the health situation in a country from public WHO and ECDC data | Claude (Anthropic) | Visible notice that the text was generated by a model | Editorial review before publication, reporting route for errors |
| Site content translation | Translates content into 15 languages | Claude (Anthropic) | Machine-translated content is marked as such | Editorial review of legal and medical content |
| Provider description translation | Translates the service descriptions a provider enters | Claude (Anthropic) | The provider sees that the text came from machine translation | The provider approves every text before publication |
| Voice assistant (demo and pilot) | Talks to a caller about scheduling: appointments, cancellations, practical information | ElevenLabs Conversational AI | A statement that the other party is a machine, given before the conversation starts | Handover to a person on request; the provider switches the feature on and off |
| City clustering by medical profile | Gives a city a descriptive label and enables filtering | K-Means (in-house model) | A descriptive label shown next to the city | Clustering output reviewed when data is refreshed |
Talking to the voice assistant
This is the only system where you interact directly with a machine, so we treat it separately.
- You are told up front. Before you start speaking you hear or see that you are talking to an automated assistant, not a member of the front-desk team.
- You can ask for a person at any point. A request to be put through to a member of staff ends the conversation with the machine.
- The scope is administrative: booking, rescheduling and cancelling appointments, opening hours, how to prepare for a visit, the provider's price list.
- What the assistant does not do: it does not assess symptoms, does not advise on treatment, does not qualify anyone for a vaccination and does not take emergency calls. If life is at risk, hang up and call the emergency number 112.
- Recordings and transcripts are processed on behalf of the provider, which is their controller, for the period it sets. You are told about recording before the conversation begins.
- Demonstration material is published only with the participants' consent and after removing anything that could identify a person.
What looks like AI but is not
These features run on rules and formulas, not on a machine-learned model. We say so plainly, because „AI” is often used as decoration and here it has legal consequences:
- The country health score is an explicit weighted formula computed in the database from public indicators. There is no learning model behind it, and the methodology and thresholds are documented on each country page.
- Outbreak alerts come from CDC and WHO feeds, filtered by keyword rules and checked by a person.
- The order of providers in search results is a weighted sum: query relevance, distance, ratings, profile completeness. We do not profile you as a person and we do not sell positions in organic results.
- Messages between a patient and a provider are written by people. We do not generate front-desk replies on a provider's behalf.
We also hold two machine-learned models whose output nobody currently sees: a country health risk model and an anomaly detector for outbreak data. They run in the background and their output feeds no screen and no programming interface. We record them here so the register is complete; if their output were ever to reach users, this document would change first.
Lines we do not cross
The following are deliberately excluded from Medova. Not because we could not build them, but because they would make our software a medical device requiring certification, and we do not hold that certification:
- Symptom triage. The assistant does not ask about symptoms and does not route people to a specialist on that basis.
- Individual vaccination intervals and schedules derived from patient parameters. Vaccination information is given as general guidance based on WHO recommendations, never as a recommendation for a specific person.
- Automatic drafting of medical records from a recording of a visit.
- Scoring a patient in a way that affects access to a service. We do not refuse bookings or vary conditions on the basis of an algorithm's output.
A disclaimer in the terms would not change how such a feature is classified, so we handle it at the level of product scope rather than wording.
What happens to data that reaches a model
- We do not train models on your data or on providers' patient data. The model vendors we use operate for us in a zero-retention mode and do not learn from what we send.
- We send the minimum: translation receives the text to be translated, not your account context or a patient history.
- Model vendors appear in the list of processors in the Privacy Policy, together with data location and the basis for any transfer outside the European Economic Area.
- Sensitive data is not sent to models for marketing or analytics purposes.
Oversight, review and reporting errors
- The AI systems register is maintained internally and reviewed quarterly. Every system has a named owner, a risk description and a defined mode of human oversight.
- Staff competence. In line with Article 4 of the AI Act we train the people who build and operate these systems, and we document that training.
- Reporting an error: if model-generated content is untrue or misleading, write to office@medova.health. We check the report and correct or remove the content.
- The right to a human: you may request human contact about any automated output by writing to dpo@medova.health.
Changes and status of this document
We update this document when a new AI system enters the service or the role of an existing one changes. The date at the top is the date the current version takes effect.
The version of 16 September 2026 is the first public version of this document. Until now we met the transparency obligation only through labels on individual features and through internal documentation.
Questions go to office@medova.health, or to dpo@medova.health where they concern personal data.
