Legal, privacy & trust
How we handle your data, the contracts for using Nixi AI, and the paperwork German law requires us to publish.
General Terms and Conditions (GTC)
The contract between Nixi AI and the practices and clinics using the service.
Read the GTCData Processing Agreement (DPA)
Accepted electronically at sign-up. Governs how Nixi AI processes patient data on behalf of your practice.
Read the DPASub-processors
Which providers process which data, for what purpose and in which data centre.
View the listPrivacy Policy for the Service
How we process the personal data of people using the application: recipients, third-country transfers, retention and your rights.
Read the privacy policyPatient consent
Consent form to sign and waiting-room notice as PDFs, plus guidance for the practice.
View guidance and PDFsPrivacy Policy
What personal data we process on this website, why, and the rights you have under the GDPR.
Read the privacy policyPatient Information
A plain-language FAQ for patients whose doctor uses Nixi AI during the consultation.
Read the patient FAQImprint
The legally required disclosure of who operates this website, per § 5 DDG.
View the imprintSecurity & Privacy
Certifications, sub-processors, audit-ready documents and the full GDPR explainer. On dedicated surfaces for IT / DPO teams and for clinicians.
Open the Security & Privacy
Technical and organisational measures (TOMs) and the DPIA guidance are available on request from privacy@nixiai.ai.
How we keep patient data safe
Built for European healthcare
Nixi AI is designed around the compliance obligations that clinicians and hospitals in Germany, Austria, and Switzerland actually face. Not retrofitted after the fact.
- GDPR (DSGVO) compliant by design
- BSI C5 controls on our processing infrastructure
- Information security management aligned to ISO/IEC 27001 (certification in progress)
- All data centres in the EU or Switzerland (adequacy decision, Art. 45 GDPR)