ZorgTekstAI
Compliance

Hoe gegevens worden beschermd.

Deze samenvatting beschrijft de feitelijke gegevensstroom en de relevante contractuele waarborgen. De infrastructuur ondersteunt AVG-verplichtingen; dit is geen zelfstandige certificering van deze applicatie.

Afbakening toepassing

Geen zelfstandig klinisch beslissysteem

De applicatie biedt uitsluitend administratieve ondersteuning en informatievoorziening. Zij diagnosticeert, triëert en schrijft niet voor en neemt geen zelfstandige behandel- of andere klinische besluiten. Iedere uitkomst is een AI-concept dat vóór gebruik inhoudelijk door een zorgprofessional moet worden gecontroleerd.

Alleen gecontroleerde output mag in een medisch dossier worden opgenomen. De zorgprofessional blijft verantwoordelijk voor juistheid, volledigheid, relevantie en noodzakelijkheid.

Privacyverklaring

Verantwoordelijke, grondslagen en rechten

Beheerder ZorgTekstAI is verantwoordelijk voor toegangsbeheer, beveiliging en functionele beheergegevens. Zelfstandige praktijken blijven verantwoordelijk voor de cliënt- en patiëntgegevens die hun gebruikers invoeren; voor die inhoud verwerkt de applicatie uitsluitend op instructie.

Geen beheerderstoegang tot patiëntgegevens. De beheerder van ZorgTekstAI kan documenten, tekst, audio, transcripties, prompts en AI-antwoorden niet inzien of ophalen. Deze inhoud wordt uitsluitend tijdelijk voor de actieve aanvraag verwerkt, niet door de applicatie opgeslagen en alleen in de actieve browsersessie aan de gebruiker getoond.

De volledige privacyverklaring beschrijft contactgegevens, doeleinden, grondslagen, ontvangers, bewaartermijnen, privacyrechten en de klachtenroute.

Gevoelige inhoud

Minimale, tijdelijke applicatieopslag

Documenten, geplakte tekst, audio, transcripties, prompts en antwoorden worden alleen tijdens de aanvraag in geheugen of kortstondige containeropslag verwerkt. De chatgeschiedenis bestaat alleen in het geheugen van de geopende pagina.

Chatbijlagen worden tijdelijk naar de applicatie gestuurd voor dezelfde veilige documentverwerking als gewone uploads. Gescande PDF-pagina's en foto's krijgen daarbij zo nodig OCR via Scaleway in Parijs. Het bestand en de uitgelezen tekst worden niet door de applicatie opgeslagen.

Uitsluitend bij de optionele QR-route worden paginafoto's tijdelijk versleuteld in Object Storage in Amsterdam gezet om ze veilig tussen telefoon en computer over te dragen. De link verloopt na 30 minuten; de foto's worden bij overname of annuleren direct verwijderd. Verlopen sessies worden opportunistisch opgeruimd en een Object Storage-lifecycle van één dag is het onafhankelijke vangnet.

Daarnaast worden algemene templates, bronnenlijsten, gehashte dagtellers en de inhoudsvrije beveiligingsaudit versleuteld bewaard in Object Storage. Templates en bronnenlijsten horen geen cliënt- of patiëntgegevens te bevatten.

Inhoudsvrije audit

Beveiligingshandelingen zonder medische inhoud

De audit slaat datum en tijd, de gebruikersnaam, een gehashte gebruikers-ID, gebeurtenistype, uitkomst en beperkte technische metadata op. Voorbeelden zijn login, logout, type AI-handeling, wijzigingen aan templates of bronnenlijsten, beheerbesluiten, opname starten, lokaal downloaden en automatische idle-logout.

Documenten, prompts, antwoorden, audio, transcripties, medische inhoud en zoektermen worden nooit in de audit opgeslagen. Auditgegevens worden maximaal 180 dagen bewaard en automatisch verwijderd. Alleen Beheerder ZorgTekstAI kan het auditoverzicht bekijken.

EU-gegevensstroom

Amsterdam en Parijs

De webapp draait op Scaleway Serverless Containers in Amsterdam. De vaste AI-endpoint verwerkt tekst, gescande PDF-pagina's en audio met Scaleway Generative APIs in Parijs. Scaleway verklaart dat alle aangeboden modellen daar worden gehost, zonder interactie met diensten van modelleveranciers.

De kernverwerking van gevoelige inhoud blijft binnen Scaleway in de EU. Optioneel internetzoeken is een afzonderlijke route: een zoekterm gaat dan naar Brave Software Inc. in de Verenigde Staten en valt niet onder de EU-only gegevensstroom. Brave kan zoekopdrachten maximaal 90 dagen bewaren en sluit zoekquerygegevens volgens zijn privacyverklaring uit van de DPA. Gebruik deze functie daarom nooit voor namen, medische informatie of andere persoonsgegevens. Google ontvangt voor de login alleen account- en authenticatiemetadata, nooit documenten, audio, prompts of AI-antwoorden.

AVG / GDPR

Verwerker, instructies en beveiliging

De DPA kwalificeert Scaleway als verwerker of subverwerker. Relevante bepalingen gaan over verwerking op gedocumenteerde instructie, vertrouwelijkheid, subverwerkers, beveiligingsmaatregelen, datalekmelding, EU-datalocatie, auditrechten en verwijdering na het contract.

De DPA bepaalt dat diensten standaard in de EU staan. Bij diensten met regiokeuze blijft de klant verantwoordelijk voor de gekozen EU-regio. Een eventuele doorgifte buiten de EU moet vooraf worden gemeld en vereist passende AVG-waarborgen.

AI-bewaarbeleid

Standaard geen prompts of outputs bewaard

De AI-voorwaarden bepalen dat gewone aanvragen en gegenereerde inhoud na verwerking niet worden bewaard, niet voor modeltraining worden gebruikt en niet toegankelijk zijn voor modelleveranciers of andere externe diensten. Deze applicatie gebruikt geen batchverwerking.

Er is één expliciete uitzondering: bij vermoed misbruik of een fout die de dienstverlening raakt, kan Scaleway tijdelijk de volledige HTTP-request bewaren voor onderzoek. De AI-privacydocumentatie noemt hiervoor een maximum van twee weken. Daarom wordt niet beweerd dat inhoud onder alle omstandigheden letterlijk nooit tijdelijk kan worden vastgehouden.

ISO/IEC 27001:2022

Gecertificeerd informatiebeveiligingsmanagement

Scaleway verklaart een ISO/IEC 27001:2022-gecertificeerd ISMS te voeren. De technische en organisatorische maatregelen beschrijven onder meer jaarlijkse interne en externe audits, toegangsbeheer volgens least privilege, logging, versleuteling, incidentrespons en toezicht op subverwerkers.

Het openbare Trust Center bevat het door BSI afgegeven ISO-certificaat. Het onderliggende auditrapport is niet openbaar: volgens DPA-artikel 12 zijn auditresultaten vertrouwelijk en kunnen aanvullende stukken op verzoek, doorgaans onder NDA, worden verstrekt.

Gebruikte componenten

Afbakening van de architectuur

  • Serverless Containers en Container Registry: applicatie en image in nl-ams; runtime-opslag is tijdelijk.
  • Generative APIs: Mistral Small 3.2 voor tekst, Mistral Medium 3.5 voor OCR/beeldherkenning en Whisper Large v3 voor audio in Parijs, uitsluitend via TLS en een beperkte API-key.
  • Lokale spraaksegmentering: de browser herkent natuurlijke spreekpauzes lokaal en verstuurt alleen gedetecteerde spraak. Bij lang doorpraten wordt een spraakfragment uiterlijk na circa 26 seconden verwerkt; de segmentering maakt geen verbinding met een externe CDN of AI-dienst.
  • Object Storage: templates, bronnenlijsten, gehashte gebruikstellers, de inhoudsvrije beveiligingsaudit en uitsluitend voor de QR-route tijdelijke, versleutelde paginafoto's in nl-ams. Foto's worden normaal direct verwijderd; de link verloopt na 30 minuten en een lifecycle van één dag is het vangnet.
  • Google OAuth: authenticatie van toegestane accounts; geen toegang tot verwerkte inhoud.
  • Tijdelijke chatbijlagen: PDF-, Word-, tekst- en afbeeldingsbestanden gebruiken dezelfde tijdelijke document- en OCR-route als gewone uploads. Bestanden en uitgelezen tekst worden na verwerking niet door de applicatie opgeslagen.
  • Brave Search: optioneel voor algemene zoekvragen binnen gekozen brondomeinen of op het hele openbare internet. Bij onbeperkt zoeken is er geen domeinfilter. De functie is uitgesloten voor gevoelige inhoud omdat zoektermen Scaleway verlaten.

Bronnen en contractversies gecontroleerd op 23 juli 2026. Zie de privacyverklaring voor de verdeling van verantwoordelijkheden, grondslagen, bewaartermijnen, privacyrechten en klachtenroute.

Compliance

How data is protected.

This summary describes the actual data flow and relevant contractual safeguards. The infrastructure supports GDPR obligations; it does not independently certify this application.

Application scope

Not an autonomous clinical decision system

The application provides administrative support and information only. It does not diagnose, triage, prescribe or make autonomous treatment or other clinical decisions. Every result is an AI draft that a healthcare professional must review substantively before use.

Only reviewed output may be entered into a medical record. The healthcare professional remains responsible for its accuracy, completeness, relevance and necessity.

Privacy statement

Controller, legal bases and rights

The ZorgTekstAI administrator is responsible for access management, security and functional administration data. Independent practices remain responsible for client and patient data entered by their users; the application processes that content solely on their instructions.

No administrator access to patient data. The ZorgTekstAI administrator cannot view or retrieve documents, text, audio, transcripts, prompts or AI responses. This content is processed only temporarily for the active request, is not stored by the application, and is shown only to the user in their active browser session.

The full privacy statement describes contact details, purposes, legal bases, recipients, retention periods, privacy rights and the complaints route.

Sensitive content

Minimal, temporary application storage

Documents, pasted text, audio, transcripts, prompts and responses are processed only during the request in memory or short-lived container storage. Chat history exists only in the memory of the open page.

Chat attachments use the same temporary, secure document-processing route as regular uploads. Where necessary, scanned PDF pages and photos receive OCR through Scaleway in Paris. The file and extracted text are not stored by the application.

Only the optional QR route stores page photos temporarily and encrypted in Object Storage in Amsterdam to transfer them securely between phone and computer. The link expires after 30 minutes; photos are deleted immediately on collection or cancellation. Expired sessions are cleaned up opportunistically and a one-day Object Storage lifecycle is the independent fallback.

General templates, source lists, hashed daily counters and the content-free security audit are stored encrypted in Object Storage. Templates and source lists must not contain client or patient data.

Content-free audit

Security events without medical content

The audit stores date and time, the username, a hashed user ID, event type, outcome and limited technical metadata. Examples include login, logout, AI action type, changes to templates or source lists, administrative decisions, starting a recording, local download and automatic idle logout.

Documents, prompts, responses, audio, transcripts, medical content and search terms are never stored in the audit. Audit data is retained for no more than 180 days and then deleted automatically. Only the ZorgTekstAI administrator can view the audit overview.

EU data flow

Amsterdam and Paris

The web application runs on Scaleway Serverless Containers in Amsterdam. The fixed AI endpoint processes text, scanned PDF pages and audio through Scaleway Generative APIs in Paris. Scaleway states that all offered models are hosted there without interaction with model-provider services.

The core processing of sensitive content remains within Scaleway in the EU. Optional internet search is a separate route: a search term is sent to Brave Software Inc. in the United States and is not part of the EU-only data flow. Brave may retain searches for up to 90 days and excludes search-query data from its DPA according to its privacy statement. Never use this function for names, medical information or other personal data. For sign-in, Google receives account and authentication metadata only, never documents, audio, prompts or AI responses.

GDPR

Processor, instructions and security

The DPA qualifies Scaleway as a processor or subprocessor. Relevant provisions concern processing on documented instructions, confidentiality, subprocessors, security measures, breach notification, EU data location, audit rights and deletion after the contract ends.

The DPA states that services are located in the EU by default. For services with a region choice, the customer remains responsible for choosing an EU region. Any transfer outside the EU must be notified in advance and requires appropriate GDPR safeguards.

AI retention policy

Prompts and outputs are not retained by default

The AI terms state that standard requests and generated content are not retained after processing, are not used for model training and are not accessible to model providers or other external services. This application does not use batch processing.

There is one explicit exception: if abuse is suspected or an error affects the service, Scaleway may temporarily retain the complete HTTP request for investigation. The AI privacy documentation specifies a maximum of two weeks. We therefore do not claim that content can literally never be retained temporarily in every circumstance.

ISO/IEC 27001:2022

Certified information security management

Scaleway states that it operates an ISO/IEC 27001:2022-certified ISMS. Its technical and organisational measures describe annual internal and external audits, least-privilege access management, logging, encryption, incident response and oversight of subprocessors.

The public Trust Center contains the ISO certificate issued by BSI. The underlying audit report is not public: under DPA Article 12, audit results are confidential and additional documents can be provided on request, generally under an NDA.

Components used

Architecture scope

  • Serverless Containers and Container Registry: application and image in nl-ams; runtime storage is temporary.
  • Generative APIs: Mistral Small 3.2 for text, Mistral Medium 3.5 for OCR/image recognition and Whisper Large v3 for audio in Paris, exclusively over TLS using a restricted API key.
  • Local speech segmentation: the browser detects natural speech pauses locally and sends only detected speech. During continuous speech, a speech fragment is processed after approximately 26 seconds at the latest; segmentation does not connect to an external CDN or AI service.
  • Object Storage: templates, source lists, hashed daily counters, the content-free security audit and—only for the QR route—temporary, encrypted page photos in nl-ams. Photos are normally deleted immediately; the link expires after 30 minutes and a one-day lifecycle is the fallback.
  • Google OAuth: authentication of approved accounts; no access to processed content.
  • Temporary chat attachments: PDF, Word, text and image files use the same temporary document and OCR route as regular uploads. Files and extracted text are not stored by the application after processing.
  • Brave Search: optional for general queries within selected source domains or across the public internet. With unrestricted search there is no domain filter. The function is excluded for sensitive content because search terms leave Scaleway.

Sources and contract versions checked on 23 July 2026. See the privacy statement for the allocation of responsibilities, legal bases, retention periods, privacy rights and the complaints route.