About us
Avidemic AB is a Swedish software company. We build AI tools for people whose work depends on reading, writing and analysis: researchers, students and clinicians. Our approach is the same across every product. AI should assist expert work, not replace it, and it should never come at the cost of privacy. All customer data is hosted within the EU, processed in line with the GDPR, and never used to train AI models.
Validemic grew out of a decade of working with universities: after hundreds of procurement and compliance reviews of our own products, we built the tool we wished every university had.
More about Avidemic at avidemic.comOur products are used at universities and healthcare organizations around the world.
Institutional clients include the University of Helsinki and the University of Turku, and we collaborate with Vejle Hospital in Denmark on clinical work.
Avidemic is listed in Ilona IT’s GDPR Library, the vendor-vetting resource Finnish public organizations use to review software suppliers.
Focused AI tools that help researchers and clinicians read, write and analyze, with every product hosted in the EU and never trained on user data.
AI for research writing, reading and analysis, used by researchers and students worldwide.
An AI-native research workspace where an agent works alongside your paper library and manuscript.
AI clinical documentation that is GDPR- and HIPAA-first, built for healthcare environments.
Vendor compliance for universities: the product you are looking at.
Validemic is built to pass the same review it runs on other vendors. The essentials:
Avidemic AB is a Swedish company under EU law. We act as a processor under Art. 28 GDPR and sign a data processing agreement with every institutional customer.
Application data, documents and backups stay in the EU, with primary hosting in Sweden. Nothing is stored outside the EU.
All our subprocessors are EU companies, listed openly with purpose, location and safeguards. No third-country transfers, so no SCCs or transfer impact assessments are needed.
Your documents are processed only to deliver the service. Neither we nor our AI providers use them to train models.
The questions DPOs, IT and procurement ask us most often, answered the same way we answer them in security questionnaires.
No. Validemic sends no data to OpenAI, Anthropic, Google or any other US model API. We use open-source models served from EU infrastructure by European providers: TensorX in Ireland and Finland as primary, with Berget AI in Sweden as automatic fallback.
We use open-weight models that we select and can replace at any time. They run on EU hardware under EU jurisdiction, operated by European sovereign-AI providers. Model choice never changes where your data is processed: it stays in the EU.
No. Prompts and completions are processed in memory, never stored or logged by our AI providers, and never used to train models. The same applies to us: we do not train anything on customer data.
On EU servers: primary hosting with Hostup in Stockholm, Sweden, and encrypted backups with Hetzner in Helsinki, Finland. No customer data leaves the EU/EEA.
Encryption in transit (TLS 1.2+), encrypted nightly backups, role-based access, and hosting providers under European ownership with no non-EU parent company. That keeps your data out of reach of extraterritorial laws such as the US CLOUD Act.
Yes. We sign an Art. 28 GDPR data processing agreement with every institutional customer and routinely complete security and procurement questionnaires as part of institutional procurement.
Yes. You can export everything in open formats at any time, and we delete data on request within a defined retention window. Everything you upload remains your property.
A short, fully published list of EU companies: hosting in Sweden, encrypted backups in Finland, two European AI inference providers, and a European email provider. The complete list with purposes and safeguards is on the compliance page, and we notify customers before any change.
Our Trust & Compliance page covers hosting, subprocessors and GDPR in detail, and we are happy to complete security questionnaires and sign DPAs.