Is Nixi AI secure enough for my practice?
Compliance posture.
The legal frameworks and infrastructure standards Nixi AI adheres to. Where we stand. With data, not marketing claims.
Legal & regulatory compliance
GDPR
Data processor under Art. 28. DPA is part of every contract.
✓ Full§203 StGB
Nixi AI is integrated as an 'auxiliary person' (§203 para. 3 StGB, 2017 reform) into medical confidentiality.
✓ Integrated§393 SGB V
Requires a current BSI C5 attestation for cloud processing of social and health data; tightened since July 2025. Nixi AI runs on attested infrastructure; its own C5 attestation is in preparation.
✓ FulfilledEU AI Act
Transparency obligations (Art. 50) from 2 August 2026. High-risk obligations from 2 December 2027 (Annex III) and 2 August 2028 (Annex I) — not applicable to Nixi AI.
◐ In Progress
Infrastructure compliance
BSI C5
Nixi AI runs on BSI C5-certified cloud infrastructure. Nixi AI itself does not hold a C5 attestation.¹
✓ Infrastructure
¹ The C5 certification refers to the cloud infrastructure provider, not to Nixi AI itself.
Hosting and Data Architecture.
Nixi AI stores patient data in Frankfurt, and uploaded documents and generated files in the Netherlands. Processing takes place in data centres in the EU and in Switzerland, not in data centres in the USA. Transmission is encrypted with TLS, stored data are encrypted by the provider, and Nixi AI additionally encrypts sensitive content fields with AES-256-GCM. The cloud infrastructure carries BSI C5 attestation.
| Location | Storage in Frankfurt, files in the Netherlands · processing in the EU and Switzerland |
| Jurisdiction | German law (StGB, DDG, GDPR) |
| Encryption at rest | By the provider · sensitive content fields additionally AES-256-GCM |
| Encryption in transit | TLS |
| USA | No processing in US data centres · providers based in the USA: Data Privacy Framework and Standard Contractual Clauses (DPA § 7) |
| On-premise option | On request, Enterprise tier |
Data Flow
Consultation
The doctor speaks with the patient. Nixi AI listens via microphone.
No permanent audio storage on the device
Encrypted Transfer
Audio is transmitted over an encrypted connection (TLS) to Nixi AI's servers in Frankfurt.
Processing
Microsoft Azure AI Speech (Germany) transcribes the audio. Microsoft Azure OpenAI (Germany, France, Sweden, Switzerland) generates the note draft.
Result
The finished draft is sent back encrypted. The doctor reviews, corrects, and approves.
Audio Deletion
The audio recording is stored temporarily in encrypted form and deleted automatically: on the server after 72 hours, and the backup copy in the browser after 4 hours at the latest.
For enterprise customers with strict internal IT policies, we offer on-premise installation on request. All data stays entirely within your own infrastructure.
What Nixi AI deliberately does not do.
Four things we contractually exclude. Spelled out in the DPA.
No permanent audio storage.
The audio recording is stored temporarily in encrypted form and deleted automatically: on the server after 72 hours, and the backup copy in the browser after 4 hours at the latest (DPA Annex 1).
No processing in US data centres.
Processing takes place in data centres in the EU and in Switzerland. For providers based in the USA, the EU-US Data Privacy Framework and EU Standard Contractual Clauses apply (DPA § 7).
No sharing with third parties.
Nixi AI processes patient data only for documentation and on your instructions (DPA §§ 1, 2). No sharing with advertising partners, data brokers or research institutions.
No autonomous clinical decisions.
Nixi AI creates a documentation draft. The doctor reviews, corrects, and approves. Nixi AI makes no diagnostic or therapeutic decisions.
Compliance Documents: Everything in one place.
All documents your data protection officer, IT department or audit requires.
Enterprise RFI Pack
Pre-assembled procurement pack for hospitals + MVZ networks: architecture diagram, BSI C5 attestation reference, DPA with annexes, Art. 30 record, TOM summary, and model-card document for Dedicated / On-Premise deployments.
Data Processing Agreement (DPA)
Accepted electronically at sign-up, and no signature is needed (Art. 28(9) GDPR). Covers processing purpose, instructions, sub-processors, deletion, the use of anonymised data and audit rights.
General Terms and Conditions (GTC)
The contract between Nixi AI and the practices and clinics using the service.
Privacy Policy for the Service
How Nixi AI processes data in the product. Separate from the website privacy policy.
Patient consent
Consent form to sign, waiting-room notice and guidance for the practice.
DPIA Guidance
Guidance to fill in for your Data Protection Impact Assessment under Art. 35 GDPR.
List of Sub-processors
Which providers process which data, for what purpose and in which data centre.
Technical and Organisational Measures (TOMs)
Summary of technical and organisational security measures under Art. 32 GDPR.
These documents do not constitute legal advice. Coordinate implementation with your data protection officer.
Sub-processors.
The service providers Nixi AI uses to operate the product. Each processes data on our behalf under contract per Art. 28 GDPR. Matches the list in the Privacy Policy.
Microsoft AzureAI processing
AI services.
EU (Frankfurt)
EUGoogle Cloud (Vertex AI)AI model
AI services.
EU
EUStripePaymentsNo PHI
Payment processing.
EU + US (SCC/DPF)
EU+USSentryError monitoringNo PHI
Error monitoring.
EU
EUMailgun (Sinch)Transactional emailNo PHI
Transactional email.
EU
EU
Marketing-site processors (analytics) are listed in the Website Privacy Policy. The demo scheduler is first-party (self-operated, no third party).
Frequently Asked Questions about Security and Compliance
Where is my patient data stored?
Nixi AI stores transcripts, notes, letters and other patient data in Google Cloud in Frankfurt, and uploaded documents and generated files in the Netherlands. The data are processed in data centres in the EU (Germany, France, Sweden, Netherlands) and in Switzerland, for which an adequacy decision of the European Commission exists, and not in data centres in the USA (DPA § 7). Transmission is encrypted with TLS, stored data are encrypted by the provider, and Nixi AI additionally encrypts sensitive content fields with AES-256-GCM.
Does Nixi AI have a BSI C5 certificate?
Nixi AI runs on BSI C5-certified cloud infrastructure. The C5 certification refers to the infrastructure provider, not Nixi AI itself. We deliberately disclose this distinction.
Is my patient data used to improve the service?
Audio recordings are deleted after 72 hours. Only anonymised data may be used to improve the service; personal data is not used for this (DPA § 12). Anonymised data are data that no longer relate to an identifiable person.
How is medical confidentiality under §203 StGB maintained?
Nixi AI is integrated as an 'auxiliary person' under §203 para. 3 StGB (2017 reform) into medical confidentiality. The DPA contains the obligation to data secrecy. This is the same mechanism used by EMR providers and billing services.
Can I audit Nixi AI?
Yes. Nixi AI makes available all information needed to demonstrate compliance with Art. 28 GDPR and allows audits, including by an auditor you mandate. Evidence is provided primarily through documentation such as the TOMs and the providers' audit reports. On-site audits are possible with 30 days' notice, as a rule no more than once a year, or more often where there is a specific reason (DPA § 15).
What happens to audio after documentation?
The audio recording is stored temporarily in encrypted form and deleted automatically: on Nixi AI's servers in Frankfurt after 72 hours, and the encrypted backup copy in the browser after 4 hours at the latest (DPA Annex 1).
Updates.
Recent changes to Nixi AI's security and privacy posture. Newest first.
Data protection pack version 2.0 published
The DPA, the list of sub-processors, the GTC and the Privacy Policy for the Service are published in version 2.0 under Legal, each as a page and a PDF, together with the patient consent template. The DPA is accepted electronically at sign-up. The TOMs and the DPIA guidance are available on request.
DPA request flow consolidated
The dedicated /legal/request-dpa page was retired. Visitors now request the DPA (and every other compliance document) from this page's modal-driven document checklist.