Application scope
Not an autonomous clinical decision system
The application provides administrative support and information only. It does not diagnose, triage, prescribe or make autonomous treatment or other clinical decisions. Every result is an AI draft that a healthcare professional must review substantively before use.
Only reviewed output may be entered into a medical record. The healthcare professional remains responsible for its accuracy, completeness, relevance and necessity.
Privacy statement
Controller, legal bases and rights
The ZorgTekstAI administrator is responsible for access management, security and functional administration data. Independent practices remain responsible for client and patient data entered by their users; the application processes that content solely on their instructions.
No administrator access to patient data. The ZorgTekstAI administrator cannot view or retrieve documents, text, audio, transcripts, prompts or AI responses. This content is processed only temporarily for the active request, is not stored by the application, and is shown only to the user in their active browser session.
The full privacy statement describes contact details, purposes, legal bases, recipients, retention periods, privacy rights and the complaints route.
Sensitive content
Minimal, temporary application storage
Documents, pasted text, audio, transcripts, prompts and responses are processed only during the request in memory or short-lived container storage. Chat history exists only in the memory of the open page.
Chat attachments use the same temporary, secure document-processing route as regular uploads. Where necessary, scanned PDF pages and photos receive OCR through Scaleway in Paris. The file and extracted text are not stored by the application.
Only the optional QR route stores page photos temporarily and encrypted in Object Storage in Amsterdam to transfer them securely between phone and computer. The link expires after 30 minutes; photos are deleted immediately on collection or cancellation. Expired sessions are cleaned up opportunistically and a one-day Object Storage lifecycle is the independent fallback.
General templates, source lists, hashed daily counters and the content-free security audit are stored encrypted in Object Storage. Templates and source lists must not contain client or patient data.
Content-free audit
Security events without medical content
The audit stores date and time, the username, a hashed user ID, event type, outcome and limited technical metadata. Examples include login, logout, AI action type, changes to templates or source lists, administrative decisions, starting a recording, local download and automatic idle logout.
Documents, prompts, responses, audio, transcripts, medical content and search terms are never stored in the audit. Audit data is retained for no more than 180 days and then deleted automatically. Only the ZorgTekstAI administrator can view the audit overview.
EU data flow
Amsterdam and Paris
The web application runs on Scaleway Serverless Containers in Amsterdam. The fixed AI endpoint processes text, scanned PDF pages and audio through Scaleway Generative APIs in Paris. Scaleway states that all offered models are hosted there without interaction with model-provider services.
The core processing of sensitive content remains within Scaleway in the EU. Optional internet search is a separate route: a search term is sent to Brave Software Inc. in the United States and is not part of the EU-only data flow. Brave may retain searches for up to 90 days and excludes search-query data from its DPA according to its privacy statement. Never use this function for names, medical information or other personal data. For sign-in, Google receives account and authentication metadata only, never documents, audio, prompts or AI responses.
GDPR
Processor, instructions and security
The DPA qualifies Scaleway as a processor or subprocessor. Relevant provisions concern processing on documented instructions, confidentiality, subprocessors, security measures, breach notification, EU data location, audit rights and deletion after the contract ends.
The DPA states that services are located in the EU by default. For services with a region choice, the customer remains responsible for choosing an EU region. Any transfer outside the EU must be notified in advance and requires appropriate GDPR safeguards.
AI retention policy
Prompts and outputs are not retained by default
The AI terms state that standard requests and generated content are not retained after processing, are not used for model training and are not accessible to model providers or other external services. This application does not use batch processing.
There is one explicit exception: if abuse is suspected or an error affects the service, Scaleway may temporarily retain the complete HTTP request for investigation. The AI privacy documentation specifies a maximum of two weeks. We therefore do not claim that content can literally never be retained temporarily in every circumstance.
ISO/IEC 27001:2022
Certified information security management
Scaleway states that it operates an ISO/IEC 27001:2022-certified ISMS. Its technical and organisational measures describe annual internal and external audits, least-privilege access management, logging, encryption, incident response and oversight of subprocessors.
The public Trust Center contains the ISO certificate issued by BSI. The underlying audit report is not public: under DPA Article 12, audit results are confidential and additional documents can be provided on request, generally under an NDA.
Components used
Architecture scope
- Serverless Containers and Container Registry: application and image in
nl-ams; runtime storage is temporary.
- Generative APIs: Mistral Small 3.2 for text, Mistral Medium 3.5 for OCR/image recognition and Whisper Large v3 for audio in Paris, exclusively over TLS using a restricted API key.
- Local speech segmentation: the browser detects natural speech pauses locally and sends only detected speech. During continuous speech, a speech fragment is processed after approximately 26 seconds at the latest; segmentation does not connect to an external CDN or AI service.
- Object Storage: templates, source lists, hashed daily counters, the content-free security audit and—only for the QR route—temporary, encrypted page photos in
nl-ams. Photos are normally deleted immediately; the link expires after 30 minutes and a one-day lifecycle is the fallback.
- Google OAuth: authentication of approved accounts; no access to processed content.
- Temporary chat attachments: PDF, Word, text and image files use the same temporary document and OCR route as regular uploads. Files and extracted text are not stored by the application after processing.
- Brave Search: optional for general queries within selected source domains or across the public internet. With unrestricted search there is no domain filter. The function is excluded for sensitive content because search terms leave Scaleway.
Sources and contract versions checked on 23 July 2026. See the privacy statement for the allocation of responsibilities, legal bases, retention periods, privacy rights and the complaints route.