Nixi AI

Privacy & Compliance

How Nixi AI protects patient data.

Data flow, medical confidentiality, EU AI Act. Explained plainly.

Where your data is, and isn't.

Five steps from microphone to documentation. The detail lives in the steps below; the short version: audio for 72 hours at most, no data centres in the USA, no selling of data.

1

Recording

You speak with your patient. Nixi AI captures the audio signal through your microphone.

2

Encrypted transfer

The audio is transmitted over TLS to Nixi AI's servers in Frankfurt.

3

Processing

Transcription runs in Germany; AI drafts are created in data centres in the EU and Switzerland.

4

Result

The finished documentation draft is sent back to you encrypted. You review, correct, and transfer it to your EMR. Practice Pro automates the transfer.

5

Audio deletion

After 72 hours, the audio is deleted automatically. The encrypted backup copy in the browser is deleted after 4 hours at the latest.

What we explicitly do NOT do

  • No permanent audio storage: recordings are deleted after 72 hours
  • No data centres in the USA: processing in the EU and Switzerland
  • No selling of data: no data brokers, no advertising networks
  • No access to full patient records: Nixi AI sees only the current consultation

Full sub-processor list and architecture in the Security & Privacy. Documentation flows directly to the EMR with Practice Pro.

Storage and deletion at a glance

One table as the single source for place and period. The values come from the data processing agreement version 2.0 (Annex 1 No. 6, § 7, § 14). The document itself is binding.

DataPeriodPlaceDeletion
Audio on Nixi AI's servers72 hoursFrankfurt am Mainautomatic
Encrypted audio backup in the browserat most 4 hoursyour workstationautomatic
Session data: transcripts, notes, letters1 to 90 days, 30 by defaultFrankfurt am Mainafter the retention period you set; custom period on Practice Pro and Enterprise
Local buffer for dictated text in the browseruntil saved, at most 7 daysyour workstationautomatic
Deleted user account30 daysFrankfurt am Mainfinal deletion
Daily backups30 daysEuropean Unionautomatic
Security and audit logs1 yearEuropean Unionautomatic
All data at the end of the contract30 daysFrankfurt am Maindeleted after the contract ends, backups at most 30 days later

Processing takes place in data centres in the EU (Germany, France, Sweden, the Netherlands) and in Switzerland, and not in data centres in the USA (§ 7 of the DPA). Once the documentation is in your practice system, your practice's retention rules apply (§ 630f BGB).

Data processing: your data, your control.

Nixi AI is a data processor under Art. 28 GDPR. That means: we process patient data exclusively on your behalf and according to your instructions. The Data Processing Agreement (DPA) is accepted electronically at sign-up and published under Legal.

What the DPA covers

Processing purposeSolely supporting medical documentation (Annex 1)
Data typesAudio recordings, transcripts, clinical notes and letters, other patient data (Annex 1)
RetentionAudio after 72 hours, session data after the retention period you set, all data at the latest 30 days after termination (§ 14)
Sub-processorsGoogle Cloud, Microsoft Azure, Mailgun and Sentry, with location and safeguards per provider (Annex 3)
Improving the serviceAnonymised data only; personal data is not used for this (§ 12)
AuditsEvidence, audit reports and on-site audits with 30 days' notice (§ 15)

DPIA support

A Data Protection Impact Assessment (DPIA, Art. 35 GDPR) may be required when introducing AI-assisted documentation with health data. Nixi AI provides DPIA guidance for you to fill in, available on request at privacy@nixiai.ai. Coordinate the DPIA with your Data Protection Officer.

Medical confidentiality: how AI documentation is compatible.

Nixi AI is integrated into medical confidentiality as a data processor, analogous to IT service providers, billing services, or cloud EMR providers that also handle patient data. The DPA contains the corresponding obligation to data secrecy.

Medical confidentiality (§203 StGB in Germany) protects the trust relationship between clinician and patient. Since the 2017 reform (§203(3) StGB), clinicians may involve so-called "auxiliary persons", including IT service providers, provided they are bound to data secrecy. Nixi AI is integrated as a technical service provider within this framework.

Why US vendors have a problem here

US companies are subject to the CLOUD Act, which grants US authorities access to data regardless of where the servers sit. This directly conflicts with §203 StGB and GDPR. As a German company based in Wiesbaden, Nixi AI is subject exclusively to German and EU law.

How Nixi AI compares to US AI tools: vendor comparison.

Do patients need to consent?

The documentation itself does not usually require consent: it is based on Art. 9(2)(h) GDPR and the medical documentation obligation. Consent covers recording the conversation (§ 201 StGB) and is obtained before the first recording. In the EULAR 2025 study, 108 patients were informed about the AI use: not a single one refused (0 refusals). 56% gave a positive response.

1

Obtain consent before the first recording

The patient signs the one-page consent form, and the original goes into the medical record. Note refusal or withdrawal with the date and document without recording from then on.

2

Put up the waiting-room notice

Nixi AI provides a one-page waiting-room notice that informs patients before their appointment.

3

Talk to your DPO

The specific assessment depends on your practice setup.

EULAR study 2025: 108 patients informed, 0 refusals, 56% positive responses, 44% neutral.

Patient information & consent form (PDF)

The one-page consent form practices use with Nixi AI: short patient information and consent to recording the conversation. Version 2.0, September 2026. Print it and have it signed before the first recording.

Download the PDF (one page) →Waiting-room notice and guidance for the practice →

EU AI Act: risk class and transparency obligations.

The EU AI Act (Regulation 2024/1689) classifies AI systems into four risk categories. As an AI documentation assistant, Nixi AI falls under "limited risk" and is subject to transparency obligations. Not the strict requirements for high-risk systems.

Risk classLimited risk
Main obligationTransparency to users (Art. 50 AI Act)
Not high-risk becauseNixi AI makes no diagnostic or therapeutic decisions. The clinician remains the decision-maker.
Applicable fromAI literacy (Art. 4) since 2 February 2025; GPAI obligations (Chapter V) since 2 August 2025; transparency (Art. 50) from 2 August 2026. The high-risk obligations were postponed by the Digital Omnibus (in force since 27 July 2026): from 2 December 2027 for stand-alone high-risk systems (Annex III) and from 2 August 2028 for systems embedded in regulated products (Annex I). What applies to Nixi AI today is the Art. 50 transparency obligation, not the high-risk regime.

We inform clinicians and patients clearly: Nixi AI is an AI system. Documentation is generated automatically, the clinician reviews and approves. No diagnostic or therapeutic decision is taken by the AI. This classification reflects Nixi AI's current product (Stage 1 ambient AI scribe). Subsequent product stages will be re-assessed under MDCG 2019-11 Rev.1 and the AI Act before launch.

Patient rights: what patients can do.

GDPR grants patients comprehensive rights over their data. Nixi AI supports you, as the clinician, in fulfilling those rights.

Art. 15

Right of access

Patients can ask what data has been processed. You provide the information from your EMR; Nixi AI provides a processing overview on request.

Art. 16

Right to rectification

Patients can request correction of inaccurate data. The AI documentation lives in your EMR. You correct it there, not at Nixi AI.

Art. 17

Right to erasure

Patients can request deletion, unless statutory retention applies (e.g. §630f BGB in Germany, 10 years).

Art. 18

Right to restriction

Patients can request processing restriction: practically relevant during open objections to AI use.

Art. 20

Right to portability

Patients can receive their data in a structured format. Nixi AI documentation lives in structured form in the EMR.

Art. 21

Right to object

Patients can object to AI documentation at any time. You then document manually, as before.

External Data Protection Officer

Nixi AI has appointed an external Data Protection Officer (DPO) under Art. 37 GDPR. Patients with access requests, complaints, or data-protection questions can reach the DPO directly.

Proliance GmbH, Dominik Fünkner

Leopoldstr. 21, 80802 München

datenschutzbeauftragter@datenschutzexperte.de

The external DPO is independent and represents the interests of data subjects. They audit our data-protection measures and are the first point of contact for supervisory authorities.

AI speech recognition and data protection: what clinicians need to know

AI speech recognition in the practice is data-protection compliant when four conditions are met: a data processing agreement under Art. 28 GDPR, processing in the EU or in countries with an adequacy decision, a confidentiality obligation under §203 StGB, and a transparent policy on data use and deletion. With Nixi AI, data is stored in Frankfurt and processed in the EU and Switzerland; audio recordings are deleted after 72 hours, and only anonymised data may be used to improve the service (DPA § 12). Crucially, this is special-category data under Art. 9 GDPR.

Speech recognition processes the spoken word from the consultation room, that is, health data of the highest protection category. Five points are decisive:

  1. 1

    Legal basis: special categories under Art. 9 GDPR.

    Health data is specially protected; in a treatment context its processing is typically permitted under Art. 9(2)(h) GDPR in conjunction with medical confidentiality.

  2. 2

    Commissioned processing: a contract under Art. 28 GDPR.

    When speech recognition is operated by a vendor, this constitutes commissioned processing. Without a data processing agreement (AVV) under Art. 28 GDPR, the use is not permitted.

  3. 3

    Place of processing: EU and Switzerland, no data centres in the USA.

    The place of processing determines the level of protection. Data centres in the EU or in countries with an adequacy decision avoid the risks of a third-country transfer. With Nixi AI, processing takes place in the EU and Switzerland, and storage in Frankfurt.

  4. 4

    Confidentiality: §203 StGB and the “other contributing person”.

    GDPR commissioned processing alone is not sufficient under criminal law. Under §203(3) StGB, vendors and subcontractors must be bound to confidentiality in writing; they then qualify as “other contributing persons”.

  5. 5

    Transparent data use and traceable deletion.

    It must be clearly governed how the data is handled and when it is deleted. With Nixi AI, audio recordings are deleted after 72 hours, and texts after the retention period the practice sets (1–90 days). Only anonymised data may be used to improve the service (DPA § 12).

Speech recognition, dictation or ambient AI: where is the data-protection difference?

Under data-protection law, the same requirements apply to all three (Art. 9, Art. 28, §203 StGB). The practical difference lies in the volume of data:

MethodData processedData-protection focus
Classic dictationThe clinician’s dictated wordAVV, server location
Speech recognitionReal-time dictationAVV, server location, deletion
Ambient AI (e.g. Nixi AI)The entire conversation incl. patient statementsPlus §203 StGB, patient consent

FAQ

Frequently asked questions about data protection

  • Yes, when the vendor does it right. Nixi AI stores data in Frankfurt, processes it in data centres in the EU and Switzerland, and works with a DPA under Art. 28 GDPR and an external DPO. This page documents how we do it.

Experience the privacy, don't just read about it. Start free.

EU-hosted infrastructure, DPA, §203-compliant. All details documented transparently. Here and in the Security & Privacy.