Built with privacy-by-design principles. GDPR-compliant workflows. Transparent data processing.
Clear responsibilities under GDPR Article 28 for transparent data processing.
Data Controller
You decide what data to process, how long to retain it, and for what purposes. You maintain full control over your customer data.
Data Processor
We process data exclusively on your instructions. We implement technical measures and support your compliance obligations.
Clear role separation under GDPR Article 28
DPA/AVV (Auftragsverarbeitungsvertrag) available for download. View DPA/AVV
Documented processing activities and technical measures
We collect only what is necessary and give you full control over retention.
We capture structured data, not raw recordings. Only the information you need is stored.
For compliance-sensitive industries, we can operate without any audio recording.
Set data retention policies that match your compliance requirements.
Request data deletion at any time with documented confirmation.
We are transparent about what data is stored, where, and for how long.
Enterprise-grade security measures to protect your data.
TLS 1.3 encryption for all data in transit
All stored data is encrypted using AES-256
Data centers in Frankfurt, Germany
Role-based access and comprehensive audit logs
Regular security assessments and updates
Documented procedures for security incidents
Designed specifically for medical practice requirements and patient data protection.
Patient calls are not recorded. Audio is processed in real-time only.
Only essential intake information is captured and stored.
Our DPA/AVV explicitly covers health data processing.
Sensitive cases are immediately escalated to your staff.
Built for German medical practices with GDPR and professional confidentiality requirements in mind.
Our Auftragsverarbeitungsvertrag defines how we process data on your behalf under GDPR Article 28. It covers processing scope, security measures, sub-processors, and your rights.
View & Download DPA/AVV Read the full agreementWe offer EU hosting options with data centers in Frankfurt, Germany. Data is processed in full compliance with GDPR requirements.
We can operate without call recording. For many workflows, we only store structured outcomes like appointment details and caller information.
A Data Processing Agreement (Auftragsverarbeitungsvertrag) defines how we process data on your behalf under GDPR Article 28. It establishes the legal framework for data processing.
Configurable retention policies and deletion procedures are built into the platform. You can request data deletion at any time with written confirmation.
Yes. We support GDPR-compliant healthcare workflows with no-recording options, structured data only, and proper controller/processor role separation.
Our team is here to answer your security and compliance questions.
security@lsm-agents.de Contact Us