Is Nixi AI secure enough for my practice?
This page summarises how Nixi AI handles security and data protection. The binding legal text lives in the Legal Documents Privacy Policy, DPA, and Imprint.
Compliance overview.
The legal frameworks and infrastructure standards Nixi AI adheres to. Where we stand. With data, not marketing claims.
Legal & regulatory compliance
GDPR
Data processor under Art. 28. DPA is part of every contract.
§203 StGB
Nixi AI is integrated as an 'auxiliary person' (§203 para. 3 StGB, 2017 reform) into medical confidentiality.
§393 SGB V
Requires a current BSI C5 attestation for cloud processing of social and health data; tightened since July 2025. Nixi AI runs on attested infrastructure; its own C5 attestation is in preparation.
EU AI Act
Transparency obligations (Art. 50) from 2 August 2026. High-risk obligations from 2 December 2027 (Annex III) and 2 August 2028 (Annex I) — not applicable to Nixi AI.
Infrastructure compliance
BSI C5
Nixi AI runs on cloud infrastructure with a BSI C5 attestation. Nixi AI itself does not hold a C5 attestation.¹
¹ The C5 attestation refers to the cloud infrastructure provider, not to Nixi AI itself.
Hosting and Data Architecture.
Nixi AI stores patient data in Frankfurt, and uploaded documents and generated files in the Netherlands. Processing takes place in data centres in the EU and in Switzerland, not in data centres in the USA. Transmission is encrypted with TLS, stored data are encrypted by the provider, and Nixi AI additionally encrypts sensitive content fields with AES-256-GCM. The cloud infrastructure carries BSI C5 attestation.
Data Flow
Consultation
The doctor speaks with the patient. Nixi AI listens via microphone.
No permanent audio storage on the device
Encrypted Transfer
Audio is transmitted over an encrypted connection (TLS) to Nixi AI's servers in Frankfurt.
Processing
Microsoft Azure AI Speech (Germany) transcribes the audio. Microsoft Azure OpenAI (Germany, France, Sweden, Switzerland) generates the note draft.
Result
The finished draft is sent back encrypted. The doctor reviews, corrects, and approves.
Audio Deletion
The audio recording is stored temporarily in encrypted form and deleted automatically: on the server after 72 hours, and the backup copy in the browser after 4 hours at the latest.
For enterprise customers with strict internal IT policies, we offer on-premise installation on request. All data stays entirely within your own infrastructure.
What Nixi AI deliberately does not do.
Four things we contractually exclude. Spelled out in the DPA.
No permanent audio storage.
The audio recording is stored temporarily in encrypted form and deleted automatically: on the server after 72 hours, and the backup copy in the browser after 4 hours at the latest (DPA Annex 1).
No processing in US data centres.
Processing takes place in data centres in the EU and in Switzerland. For providers based in the USA, the EU-US Data Privacy Framework and EU Standard Contractual Clauses apply (DPA § 7).
Only on your instructions.
Nixi AI processes patient data only for documentation and on your instructions (DPA §§ 1, 2). The service providers involved are named in the subprocessor list. No data goes to advertising partners, data brokers or research institutions.
No autonomous clinical decisions.
Nixi AI creates a documentation draft. The doctor reviews, corrects, and approves. Nixi AI makes no diagnostic or therapeutic decisions.
Compliance Documents: Everything in one place.
All documents your data protection officer, IT department or audit requires.
Data Processing Agreement (DPA)
Accepted electronically at sign-up, and no signature is needed (Art. 28(9) GDPR). Covers processing purpose, instructions, sub-processors, deletion, the use of anonymised data and audit rights.
General Terms and Conditions (GTC)
The contract between Nixi AI and the practices and clinics using the service.
Privacy Policy for the Service
How Nixi AI processes data in the product. Separate from the website privacy policy.
Patient consent
Consent form to sign, waiting-room notice and guidance for the practice.
List of Sub-processors
Which providers process which data, for what purpose and in which data centre.
Enterprise RFI Pack
Pre-assembled procurement pack for hospitals + MVZ networks: architecture diagram, BSI C5 attestation reference, DPA with annexes, Art. 30 record, TOM summary, and model-card document for Dedicated / On-Premise deployments.
DPIA Guidance
Guidance to fill in for your Data Protection Impact Assessment under Art. 35 GDPR.
Technical and Organisational Measures (TOMs)
Summary of technical and organisational security measures under Art. 32 GDPR.
These documents do not constitute legal advice. Coordinate implementation with your data protection officer.
Sub-processors.
The service providers Nixi AI uses to operate the product. Each processes data on our behalf under contract per Art. 28 GDPR. Matches the list in the Privacy Policy.
Microsoft AzureAI processing
AI services.
EU (Frankfurt)
Google Cloud (Vertex AI)AI model
AI services.
EU
Stripe Payments EuropePaymentsNo PHI
Payment processing.
Ireland. A transfer to the USA is possible, safeguarded by the EU-US Data Privacy Framework and standard contractual clauses (privacy policy, section 6).
SentryError monitoringNo PHI
Error monitoring.
Stored in Frankfurt (Germany). US company: access from the USA cannot be ruled out, safeguarded by the EU-US Data Privacy Framework and standard contractual clauses (privacy policy, section 6).
Mailgun (Sinch)Transactional emailNo PHI
Transactional email.
Servers in the EU. US company: access from the USA cannot be ruled out, safeguarded by the EU-US Data Privacy Framework and standard contractual clauses (privacy policy, section 6).
Marketing-site processors (analytics) are listed in the Website Privacy Policy. The demo scheduler is first-party (self-operated, no third party).
Updates.
Recent changes to security and data protection at Nixi AI. Newest first.
Data protection pack version 2.0 published
The DPA, the list of sub-processors, the GTC and the Privacy Policy for the Service are published in version 2.0 under Legal, each as a page and a PDF, together with the patient consent template. The DPA is accepted electronically at sign-up. The TOMs and the DPIA guidance are available on request.
DPA request flow consolidated
The dedicated /legal/request-dpa page was retired. Visitors now request the DPA (and every other compliance document) from this page's modal-driven document checklist.
Legal.
Website Privacy Policy
How the Nixi AI marketing website handles your personal data.
FAQ
Frequently Asked Questions about Security and Compliance
Nixi AI stores transcripts, notes, letters and other patient data in Google Cloud in Frankfurt, and uploaded documents and generated files in the Netherlands. The data are processed in data centres in the EU (Germany, France, Sweden, Netherlands) and in Switzerland, for which an adequacy decision of the European Commission exists, and not in data centres in the USA (DPA § 7). Transmission is encrypted with TLS, stored data are encrypted by the provider, and Nixi AI additionally encrypts sensitive content fields with AES-256-GCM.