Trust Center

Security and Privacy for Healthcare

SmartArzt processes sensitive healthcare data exclusively on European infrastructure - following GDPR, Privacy by Design, and using C5-certified cloud providers.

Compliance & Security

C5-Certified Cloud Providers

SmartArzt exclusively uses cloud providers attested under the BSI C5 catalogue - the German standard for secure cloud services in sensitive environments.

GDPR Compliance

Personal data is processed solely in accordance with GDPR. Data is deleted after processing. No sharing with third parties.

Encryption

All data is transmitted encrypted (TLS) and stored encrypted. Access is restricted to the minimum necessary.

EU AI Act Compliance

Our AI processes are continuously developed to meet the requirements of the EU AI Act for medical AI systems.

Secure Development Lifecycle

Regular penetration testing, code reviews, and ongoing security training are part of our development process.

Privacy Policy

Transparent information on data handling for all SmartArzt products. View Privacy Policy →

Architecture & Hosting

SmartArzt is built on a distributed, cloud-based architecture operated exclusively within the European Union. The platform ingests audio data, processes it using AI-driven engines, and delivers structured documentation - all within seconds.

The architecture follows a Privacy by Design approach: every subsystem - from data capture to storage - operates under strict access controls and encryption standards.

Hosting exclusively within the EU
Audio data deleted after processing
No sharing with third parties
Encrypted transmission and storage

Questions about security or compliance?

We're happy to answer specific questions about data protection, data processing agreements (DPA), or technical security details.

SmartArzt