Enterprise-grade security and GDPR compliance for AI-powered dental smile enhancement
Full compliance with EU GDPR, German TTDSG, and BDSG requirements for biometric health data processing.
Images are deleted immediately after processing. 0-second retention policy with in-memory processing only.
Database hosted in EU (Frankfurt). All persistent data remains within the EU processing region. Encrypted backups (never images) may transit non-EU Google infrastructure; the provider never holds the decryption key.
All data transmissions encrypted with latest TLS protocol. HSTS enabled with 1-year max-age.
All database records encrypted at rest using industry-standard AES-256 encryption.
Automated Let's Encrypt certificates via Vercel with auto-renewal and monitoring.
Biometric images are deleted immediately after AI processing. No persistent storage of photos.
Random session identifiers used instead of personal data. No name, email, or identifiers collected.
Only the photo itself is processed. All EXIF metadata (GPS, device info) is stripped.
Serverless architecture processes images in RAM. No disk writes or temporary files.
Three-tier access system (Admin, Agency, Dentist) with principle of least privilege.
All passwords hashed with bcrypt (10 rounds). No plaintext password storage.
Cryptographically secure tokens (32 bytes) for iframe embedding and API access.
All biometric image processing occurs within the EU using Google Cloud Vertex AI in the Netherlands (europe-west4). Your data remains within EU jurisdiction during AI processing, minimizing compliance risks and ensuring GDPR Art. 45 adequacy.
| Sub-Processor | Service | Location | Safeguards |
|---|---|---|---|
| Vercel Inc. | Hosting & Serverless Compute | 🇪🇺 EU (Frankfurt, fra1 — pinned) | EU processing region; DPA w/ SCCs as residual safeguard ✅ |
| Neon Inc. | PostgreSQL Database | 🇪🇺 EU (Frankfurt) | EU processing region; DPA w/ SCCs as residual safeguard ✅ |
| Google Cloud (Vertex AI) | AI Processing (Gemini 2.5 Flash) | 🇪🇺 EU (Netherlands) | EU processing region ✅ |
| Google Workspace (Drive) | Encrypted backup storage (interim until EU provider) | Google global infrastructure | DPF + SCCs; end-to-end encrypted — provider never holds the key |
Technical:
Organizational:
We conducted a comprehensive Transfer Impact Assessment in accordance with EDPB Recommendations 01/2020, evaluating all international data transfers. Application compute is pinned to the EU (Vercel functions, Frankfurt fra1). Residual US exposure: US-headquartered providers (Vercel, Neon) operating EU regions under DPAs with SCCs, and end-to-end-encrypted database backups stored on Google infrastructure (interim — EU provider planned before first client onboarding).
Assessment Result:
Risk Level: LOW – EU-based biometric data processing ✅
All biometric image processing occurs within the EU (Netherlands - europe-west4). Application compute (Vercel, Frankfurt fra1), database (Neon, Frankfurt) and AI processing (Netherlands) all run in EU processing regions; US-headquartered providers are covered by DPAs with SCCs as a residual safeguard.
Dental practices using ZambetAI receive comprehensive compliance documentation for audits and regulatory requirements:
Technical and Organizational Measures
757 lines documenting all security measures in accordance with Art. 32 GDPR. Includes security checklists and audit procedures.
Transfer Impact Assessment
839 lines evaluating US data transfers following EDPB Recommendations 01/2020. Includes risk matrices and supplementary measures.
Data Processing Agreement
GDPR Art. 28-compliant contract with complete sub-processor list, SCC references, and security measures summary.
Full compliance with all GDPR requirements for biometric health data processing
Cookie consent management and telemedia data protection compliance
Adherence to German national data protection requirements
Transfer Impact Assessment following EDPB guidance for international transfers
Our data protection team is here to answer your questions about security, compliance, and data protection.
Last Updated: August 17, 2026 | Version 1.1
This security page is regularly reviewed and updated to reflect current security measures and compliance standards.