Introduction
Nixi AI GmbH (hereinafter “Nixi AI”) uses the Sub-processors listed below for its platform (hereinafter “Service”). They process personal data on behalf of the practice or clinic (hereinafter “Controller”). This list is Annex 3 to the “Data Processing Agreement (DPA)”. By accepting the DPA, the Controller approves their use (§ 6 DPA).
Changes: Nixi AI announces the engagement or replacement of a Sub-processor at least 30 days in advance by email (text form). The Controller may object on data protection grounds within 14 days, for example by email to privacy@nixiai.ai. If no agreement is reached, the Controller may terminate with effect from the date of the change (special right of termination). The list is updated in this way without the DPA having to be concluded anew.
Locations: All data centres are located in the EU (Germany, France, Sweden, Netherlands) or in Switzerland, for which an adequacy decision of the European Commission exists (Art. 45 GDPR).
Last updated: 11 September 2026. The current version is available at www.nixiai.ai/legal and in the Service under Settings › Privacy („Einstellungen › Datenschutz“).
1. Google Cloud
Company & address: Google Cloud EMEA Limited, Velasco, Clanwilliam Place, Dublin 2, D02 FH61, Ireland
| Service provided | Data processed | Place of processing |
|---|---|---|
| Hosting (Cloud Run), database (Cloud SQL), key management | all data stored in the Service: transcripts, notes, letters, patient data, user data | Frankfurt, Germany (europe-west3) |
| Database backups | as for the database | EU |
| Audio storage (Cloud Storage) | audio recordings (deletion after 72 hours) | Frankfurt, Germany (europe-west3) |
| File storage (Cloud Storage) | uploaded documents and generated files (e.g. PDF) | Netherlands (europe-west4) |
| Vertex AI (Gemini): rewriting and translation of patient letters and referral letters, translation of discharge reports, EBM suggestions (beta) | the content required for the respective task (health data, where applicable identification data) | Netherlands (europe-west4) |
Safeguards: Processing in the EU · Google's Cloud Data Processing Addendum (including the provisions on data transfers) · Contractual supplement regarding § 203 StGB (German Criminal Code) (Google Cloud Professional Secrecy Addendum)
2. Microsoft Azure
Company & address: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland
| Service provided | Data processed | Place of processing |
|---|---|---|
| Azure AI Speech (speech recognition) | audio data | Germany (Germany West Central) |
| Azure OpenAI (AI drafts) | transcripts and other content required for the draft (health data, where applicable identification data) | Germany, France, Sweden, Switzerland |
| Azure Document Intelligence (text recognition in uploaded documents) | uploaded documents | Germany (Germany West Central) |
Safeguards: Processing in the EU · for Switzerland, adequacy decision of the European Commission (Art. 45 GDPR) · Microsoft Products and Services Data Protection Addendum (DPA, including the provisions on data transfers) · Supplementary agreement for professional secrecy holders (Professional Secrecy Amendment, § 203 StGB)
3. Mailgun
Company & address: Mailgun Technologies, Inc. (Sinch), 112 E. Pecan Street #1135, San Antonio, Texas 78205, USA
| Service provided | Data processed | Place of processing |
|---|---|---|
| Email delivery: service emails; documents sent by the doctor by email | email addresses and content of the emails, for documents sent also their content (where applicable health data) | EU servers |
Safeguards: Processing in the EU region · EU-US Data Privacy Framework (Art. 45 GDPR) · EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) · The provider's Data Processing Addendum
4. Sentry
Company & address: Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA
| Service provided | Data processed | Place of processing |
|---|---|---|
| Error monitoring including fully masked session recordings | technical data on errors and processes in the application; personal data are filtered, texts and inputs in session recordings are fully masked | Data storage in Frankfurt (EU region) |
Safeguards: EU data storage · EU-US Data Privacy Framework (Art. 45 GDPR) · EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) in the event that the Data Privacy Framework is not applicable · Data processing agreement concluded
Not Sub-processors
- Nixi AI's own services (e.g. coding and billing services) run in Nixi AI's own Google Cloud. They are part of the Service; the infrastructure is provided by Google Cloud (see No. 1).
- The Controller's practice management system (PVS) is not a Sub-processor of Nixi AI. Data are transferred at the Controller's initiative: by the doctor via a button or via the automatic GDT transfer, which the doctor can activate and which is deactivated by default.
- Payment processing (Stripe) and Google sign-in concern only account and contract data for which Nixi AI itself is the controller. Details are set out in the “Privacy Policy for the Service”.