Privacy and security
Courtesy translation. The German version is legally binding: German version.
The Application Copilot processes your patients’ health data. This page sets out where that data is stored, who processes it and what a language model gets to see. Anything not yet in place is marked “planned”.
The Application Copilot is not yet in live operation. This page describes the state at launch.
- GermanyStored content data at Hetzner, Nuremberg/Falkenstein
- Chiffre onlyA case code, no patient names in the system
- AI processing in GermanyC5-attested provider, no storage, no training
- Encrypted per practiceAES-256-GCM, key not in the database
1Where your data is stored
Case records, session notes, questionnaire scores and reports are stored exclusively in Germany, on servers of Hetzner Online GmbH in Nuremberg/Falkenstein. There is no secondary location outside Germany, not even for backups. The only exception is the pseudonymised excerpts that are processed briefly, also in Germany, to produce report drafts (section 3). You remain the controller within the meaning of the GDPR; we are your processor (Auftragsverarbeiter).
Hetzner holds an ISO/IEC 27001:2022 certificate and a BSI C5:2020 Type 2 attestation (Testat) for the cloud services we use. This applies to the infrastructure, not to our application. For the Application Copilot itself we have no C5 attestation and no ISO 27001 certificate. Preparation for a C5 audit (comparison against all basic criteria, action plan) is under way Planned.
Who the Application Copilot is for today. At launch it is open only to practices without a statutory-insurance licence (Kassenzulassung): private practices with self-paying clients, privately insured clients, civil-servant (Beihilfe) clients and statutorily insured clients via reimbursement (Kostenerstattung, § 13(3) SGB V). The reason is § 393 SGB V: practices with a statutory-insurance licence or authorisation may only have health data processed in the cloud if the provider holds a C5 attestation. We do not have that yet. At registration we therefore ask about a statutory-insurance licence. Practices with a statutory-insurance seat (KV-Sitz) can be added to a waitlist on request, and we notify them once, as soon as the attestation is available. If you obtain a licence later, please tell us (Terms § 1(2c)).
Operating environment during the introductory phase. The application runs on a Hetzner cloud server in Germany that we share with other web projects of ours. It is separated by its own containers, its own internal networks, its own database, its own keys and secrets; only the shared proxy is exposed. Physical separation and full-disk encryption are not in place; instead, content and backups are encrypted at application level. Before we serve a larger customer base, we will move to a dedicated server.
- Connection. Your browser or the app connects over TLS to our proxy at Hetzner.
- Checks. Our API checks login with a second factor, practice membership and permissions, and logs every event.
- Storage. PostgreSQL stores content, additionally encrypted per practice. A background process enforces deletion periods.
- Draft. For report drafts, pseudonymised excerpts go to the language model. It runs at Schwarz Digits Cloud GmbH & Co. KG (STACKIT AI Model Serving) in data centres in Germany (region eu01). The provider holds a BSI C5 Type 2 attestation, is listed as a sub-processor and is bound to confidentiality under § 203 StGB. It neither stores requests or responses nor uses them for training. We do not run a model server of our own.
- Ancillary services. Payment runs through Creem, account emails through an email service, technical errors through Sentry. None of them receives case content.
2Who processes data
The same list as in Annex 3 of our data processing agreement (AVV, Auftragsverarbeitungsvertrag). It names only providers that are actually used.
| Provider | Purpose | Location | Basis | Data categories |
|---|---|---|---|---|
| Hetzner Online GmbHGunzenhausen | Servers, database, object storage, backups, website | Germany | Processing on our behalf, Art. 28 GDPR | All content data (encrypted), account data, logs |
| Language modelmodel to be confirmed, Schwarz Digits Cloud GmbH & Co. KG (STACKIT) | Drafts for report sections and formal review notes. Dictation is not active at launch | Germany | Sub-processor, contract under Art. 28 GDPR; confidentiality undertaking under § 203 StGB | Pseudonymised excerpts, draft text |
| Resend, Inc. | Account, invitation and security emails | USA | Processing on our behalf; EU-US Data Privacy Framework, standard contractual clauses | Email address, name, text of the system email. No patient emails, no case content |
| Apple (push service APNs) | Push notifications to the iOS app | USA/Ireland | Data Privacy Framework or standard contractual clauses | Device token and fixed, generic texts. No code, no health data |
| Functional Software, Inc. (Sentry)only if enabled | Technical error reports | EU region (Frankfurt) | Processing on our behalf; standard contractual clauses | Error data without content, without user identifier |
| CreemArmitage Labs OÜ, Tallinn | Payment and invoicing (merchant of record) | Estonia | Own controller, not a sub-processor | Billing and payment data of the practice. No card data with us, no health data |
No website statistics. Not used: Google Cloud, Firebase, Anthropic or OpenAI interfaces, Groq, Cohere, Azure OpenAI, PostHog, SendGrid.
3The language model
The Application Copilot creates a draft from your records. You write and are responsible for the report. Every sentence points to its source, and unsupported sentences are marked. The software makes no diagnosis, prognosis or treatment recommendation.
- Model
- to be confirmed before launch
- Where it runs
- At Schwarz Digits Cloud GmbH & Co. KG (STACKIT AI Model Serving) in data centres in Germany (region eu01). The provider holds a BSI C5 Type 2 attestation, is listed as a sub-processor and is bound to confidentiality under § 203 StGB. It neither stores requests or responses nor uses them for training. We do not run a model server of our own.
- What it receives
- Pseudonymised excerpts from the sources of the respective section: session notes, questionnaire scores, your own entries.
- What it does not receive
- Names, addresses, contact details, insurance numbers. The case record carries only a code; names, places, employers and contact details in free text are removed before the call.
- What is stored
- The result in your case and a log without content: model, time, number of tokens, duration. The provider stores and logs no requests or responses (contractually assured, verified before launch).
- Training
- Your data is not used for training, neither by us nor by the provider.
Traceable in the app. For every generation we record which model processed where and from how many sources excerpts were sent, without content. In the version view of the report you read: “Created with [model], processed in Germany (STACKIT AI Model Serving, region eu01), sent: pseudonymised excerpts from 26 sources”. Model and operator are defined in exactly one place in our configuration; this page and the app both read from it. If the model provider changes, we announce it 30 days in advance.
4Encryption and access
- TransportImplemented
- StorageImplemented
- BackupsImplemented
- Separate backup storagePlanned
- Disk encryptionPlanned
- LoginImplemented
- Separation of practicesImplemented
- Roles under § 203 StGB (German Criminal Code, professional secrecy)Implemented
- Access by our teamPlanned for launch
- LogImplemented
- External penetration testPlanned
- C5 attestation for the applicationPlanned
5Retention and deletion
You keep the treatment record (§ 630f BGB, 10 years). We are not a retention service. Before anything is deleted, the app reminds you to transfer content into your record.
| Data | Period |
|---|---|
| Case record, notes, questionnaires, reports | You can delete at any time. Deleted items can be restored for 7 days; after that, deletion is final. |
| After the contract ends | 30 days read-only for export, then deletion of all data of the practice. |
| Backups | Expire after 35 days, no selective deletion. |
| Export files (PDF, DOCX) | Not stored permanently, 24 hours at most. |
| Questionnaire links | Usually valid for 72 hours; link data deleted after 30 days. |
| Unsubmitted life-history questionnaires | 30 days after the link expires. |
| Supervision: copy and comments | 30 days after the share ends (expiry or revocation). The record of who saw which version when stays with the case. |
| Proof of training (PiA plan) | After the follow-up proof is checked, 13 months after upload at the latest, and 30 days after the contract ends. |
| Waitlist for practices with a statutory-insurance licence | After the notification, 12 months after sign-up at the latest. Only email, time and, optionally, location. |
| Audit log | 3 years. |
| Error reports, server logs | 90 days; IP addresses in logs truncated after 7 days, logs deleted after 30 days. |
| Billing records | 10 years (§ 147 AO, German Fiscal Code), no health data. |
| At the AI provider | No storage beyond the request. |
Every deletion is logged without content. We issue a deletion confirmation on request.
6Your documents to download
All documents carry a version and a checksum. This gives your data protection adviser what they need for the record of processing activities and the impact assessment. The documents are in our application and available from launch. The documents are in German, and the German versions are legally binding.
- Data processing agreement (AVV)PDF download: data processing agreement (AVV), German
- Annex 2: technical and organisational measuresPDF download: Annex 2, technical and organisational measures, German
- Annex 3: sub-processorsPDF download: Annex 3, sub-processors, German
- Template: data protection impact assessment for your practicePDF download: template data protection impact assessment, German
- Template: confidentiality undertaking under § 203 StGBPDF download: template confidentiality undertaking under § 203 StGB, German
- Deletion conceptPDF download: deletion concept, German
- Privacy policyPDF download: privacy policy, German
7Changes
We announce new sub-processors at least 30 days in advance, by email to the practice owner and on this page. Within 14 days you can object for an important data-protection reason. If no agreement is reached, either side can terminate as of the date of the change; we refund prepaid fees pro rata.
| Date | Change |
|---|---|
| 09.10.2026 | No GPU server of our own: AI processing takes place in Germany at Schwarz Digits Cloud GmbH & Co. KG (STACKIT AI Model Serving), a C5-attested provider, with no storage and no training; listed as a sub-processor and bound under § 203 StGB. Dictation not active at launch. New versions of the AVV, privacy policy, deletion concept, patient information, confidentiality undertaking and DPIA template; deletion job for the waitlist implemented. |
| 08.10.2026 | At launch only for practices without a statutory-insurance licence (§ 393 SGB V), waitlist for practices with a statutory-insurance seat; status of the C5 preparation disclosed (no attestation, no ISO certificate); deletion periods added for supervision, proof of training and waitlist; new versions of the Terms, AVV, privacy policy and deletion concept. |
| 06.10.2026 | Language model and speech recognition run on our own GPU dedicated server at Hetzner in Germany (private tunnel), no external provider; operating environment of the application in the introductory phase disclosed; backup storage listed as “planned”. |
| 04.10.2026 | First version of this page (language model then on our own server in Germany). |
8Privacy contact
- Privacy questions
- kontakt@psyclinicai.com, subject “Datenschutz”
- Report a vulnerability
- kontakt@psyclinicai.com, subject “Sicherheit”. Please do not send patient data.
- Controller
- See imprint
Data subjects should contact the treating practice for access, rectification or deletion; we support the practice in doing so.