Security & Compliance

Enterprise-grade security and GDPR compliance for AI-powered dental smile enhancement

GDPR Compliant

Full compliance with EU GDPR, German TTDSG, and BDSG requirements for biometric health data processing.

Zero Retention

Images are deleted immediately after processing. 0-second retention policy with in-memory processing only.

EU Data Storage

Database hosted in EU (Frankfurt). All persistent data remains within the EU processing region. Encrypted backups (never images) may transit non-EU Google infrastructure; the provider never holds the decryption key.

Technical Security Measures (Art. 32 GDPR)

Encryption & Transport Security

  • TLS 1.3 End-to-End Encryption:

    All data transmissions encrypted with latest TLS protocol. HSTS enabled with 1-year max-age.

  • AES-256 Database Encryption:

    All database records encrypted at rest using industry-standard AES-256 encryption.

  • Certificate Management:

    Automated Let's Encrypt certificates via Vercel with auto-renewal and monitoring.

Data Minimization & Privacy by Design

  • Immediate Deletion (0-Second Retention):

    Biometric images are deleted immediately after AI processing. No persistent storage of photos.

  • Pseudonymization via Session IDs:

    Random session identifiers used instead of personal data. No name, email, or identifiers collected.

  • Metadata Stripping:

    Only the photo itself is processed. All EXIF metadata (GPS, device info) is stripped.

  • In-Memory Processing Only:

    Serverless architecture processes images in RAM. No disk writes or temporary files.

Access Control & Authentication

  • Role-Based Access Control (RBAC):

    Three-tier access system (Admin, Agency, Dentist) with principle of least privilege.

  • Bcrypt Password Hashing:

    All passwords hashed with bcrypt (10 rounds). No plaintext password storage.

  • Token-Based API Authentication:

    Cryptographically secure tokens (32 bytes) for iframe embedding and API access.

Organizational Security Measures

Data Protection Governance

  • ✅ Documented data protection policies
  • ✅ Data Protection Officer (DPO) appointed
  • ✅ Regular security training for personnel
  • ✅ Confidentiality commitments for all staff

Incident Response

  • ✅ 72-hour breach notification (Art. 33 GDPR)
  • ✅ 5-phase incident response plan
  • ✅ Documented escalation procedures
  • ✅ Regular security audits & penetration testing

Vendor Management

  • ✅ Careful selection of sub-processors
  • ✅ Data Processing Agreements (Art. 28) with all vendors
  • ✅ Regular vendor security assessments
  • ✅ 14-day notice for sub-processor changes

Compliance & Auditing

  • ✅ Annual security review (next: Oct 2026)
  • ✅ Quarterly compliance assessments
  • ✅ Processing activity records (Art. 30 GDPR)
  • ✅ Right to audit for dental practices

International Data Transfers (Art. 44-46 GDPR)

EU-Based AI Processing

All biometric image processing occurs within the EU using Google Cloud Vertex AI in the Netherlands (europe-west4). Your data remains within EU jurisdiction during AI processing, minimizing compliance risks and ensuring GDPR Art. 45 adequacy.

Transfer Safeguards

Sub-ProcessorServiceLocationSafeguards
Vercel Inc.Hosting & Serverless Compute🇪🇺 EU (Frankfurt, fra1 — pinned)EU processing region; DPA w/ SCCs as residual safeguard ✅
Neon Inc.PostgreSQL Database🇪🇺 EU (Frankfurt)EU processing region; DPA w/ SCCs as residual safeguard ✅
Google Cloud (Vertex AI)AI Processing (Gemini 2.5 Flash)🇪🇺 EU (Netherlands)EU processing region ✅
Google Workspace (Drive)Encrypted backup storage (interim until EU provider)Google global infrastructureDPF + SCCs; end-to-end encrypted — provider never holds the key

Supplementary Measures (EDPB Recommendations 01/2020)

Technical:

  • ✅ TLS 1.3 encryption in transit
  • ✅ 0-second retention (immediate deletion)
  • ✅ Pseudonymization (session IDs)
  • ✅ Data minimization (photo only)
  • ✅ In-memory processing (no disk writes)

Organizational:

  • ✅ Contractual commitments (SCCs, AVVs)
  • ✅ Transparency & explicit consent
  • ✅ Vendor due diligence
  • ✅ Incident response procedures
  • ✅ Annual TIA review (next: Oct 2026)

Transfer Impact Assessment (TIA)

We conducted a comprehensive Transfer Impact Assessment in accordance with EDPB Recommendations 01/2020, evaluating all international data transfers. Application compute is pinned to the EU (Vercel functions, Frankfurt fra1). Residual US exposure: US-headquartered providers (Vercel, Neon) operating EU regions under DPAs with SCCs, and end-to-end-encrypted database backups stored on Google infrastructure (interim — EU provider planned before first client onboarding).

Assessment Result:

Risk Level: LOW – EU-based biometric data processing ✅

All biometric image processing occurs within the EU (Netherlands - europe-west4). Application compute (Vercel, Frankfurt fra1), database (Neon, Frankfurt) and AI processing (Netherlands) all run in EU processing regions; US-headquartered providers are covered by DPAs with SCCs as a residual safeguard.

Compliance Documentation

Dental practices using ZambetAI receive comprehensive compliance documentation for audits and regulatory requirements:

TOMS

Technical and Organizational Measures

757 lines documenting all security measures in accordance with Art. 32 GDPR. Includes security checklists and audit procedures.

TIA

Transfer Impact Assessment

839 lines evaluating US data transfers following EDPB Recommendations 01/2020. Includes risk matrices and supplementary measures.

AVV / DPA

Data Processing Agreement

GDPR Art. 28-compliant contract with complete sub-processor list, SCC references, and security measures summary.

Standards & Best Practices

GDPR Compliance (EU 2016/679)

Full compliance with all GDPR requirements for biometric health data processing

TTDSG Compliance (German Telemedia Act)

Cookie consent management and telemedia data protection compliance

BDSG Compliance (German Federal Data Protection Act)

Adherence to German national data protection requirements

EDPB Recommendations 01/2020

Transfer Impact Assessment following EDPB guidance for international transfers

Questions about Security?

Our data protection team is here to answer your questions about security, compliance, and data protection.

Last Updated: August 17, 2026 | Version 1.1

This security page is regularly reviewed and updated to reflect current security measures and compliance standards.