Sub-processors
Synduct GmbH — DR. INFO Platform (DR. INFO Clinical & DR. INFO Workflow, including the Scribe and discharge-letter/report modules)
Last updated: 26 August 2026
Synduct GmbH ("Synduct") engages the sub-processors listed below to help provide the DR. INFO Platform to its customers (hospitals and individual healthcare professionals). All processing of customer data takes place within the EU/EEA or the United Kingdom (which benefits from an EU adequacy decision under Art. 45 GDPR). Each sub-processor is bound by a written agreement imposing data-protection obligations materially equivalent to those in our Data Processing Agreement (Art. 28 GDPR).
Notice of changes
We notify customers in writing at least 30 days in advance before adding or replacing a sub-processor. Customers may object on reasonable data-protection grounds within the notice period.
To receive advance notice of changes to this list, contact regulatory@synduct.com.
Current sub-processors
| Sub-processor | Registered seat | Purpose | Processing location | Transfer safeguard |
|---|---|---|---|---|
| Vercel Inc. | San Francisco, USA | Hosting of the web-application and website frontend (user interface). Customer and patient data is not stored on or processed by Vercel; it is handled by the EU backend (Azure). | Frontend hosting only (no patient data) | EU-U.S. Data Privacy Framework (Art. 45 GDPR); EU Standard Contractual Clauses as fallback |
| Microsoft Ireland Operations Ltd. (Microsoft Azure) | Dublin, Ireland | Backend infrastructure and application/API hosting | EU region (North Europe, Ireland) | EU-U.S. Data Privacy Framework (Art. 45 GDPR); EU Standard Contractual Clauses as fallback |
| Google Cloud EMEA Ltd. — Google Cloud Platform / Firebase (Firestore, Firebase Authentication, Compute Engine, backups) | Dublin, Ireland | Database (Firestore — stores user queries), user authentication (Firebase Auth), backups, and the pseudonymisation / masking model (Compute Engine VM) | EU region | EU-U.S. Data Privacy Framework (Art. 45 GDPR); EU Standard Contractual Clauses as fallback |
| Google Cloud EMEA Ltd. — Vertex AI (Gemini, enterprise) | Dublin, Ireland | AI inference for form/letter drafting and transcription structuring (transient processing; zero data retention; no training on customer data) | EU region | EU-U.S. Data Privacy Framework (Art. 45 GDPR); EU Standard Contractual Clauses as fallback |
| Speechmatics Ltd. | Cambridge, United Kingdom | Speech-to-text transcription for the Scribe module (transient processing; no training on customer data) | EU region (EU1) | EU-UK Adequacy Decision (Art. 45 GDPR); EU Standard Contractual Clauses as fallback |
Security & certifications
Our infrastructure and AI-service provider maintains ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018 and SOC 2 certifications. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Direct patient identifiers are removed or replaced (de-identification) before any AI-assisted processing, except for Scribe consultation audio, which is processed on the basis of explicit patient consent and cannot be masked prior to transcription.
For questions about this list or our data-protection practices, contact regulatory@synduct.com.