Security and compliance
GDPR-compliant, secure patient data handling
MediVox delivers full GDPR compliance from day one: AI disclosure, data minimisation, encryption and EU-based data storage. Patient data is safe.
100%
GDPR compliance
Full European data protection compliance from day one — AI disclosure, encryption, data minimisation.
Features
What the security and compliance module includes
GDPR compliance
MediVox is fully GDPR-compliant: an AI disclosure is announced at the start of every call, only the necessary data is collected, AES-256 encryption is used and data is stored in an EU data centre (Hetzner).
AI disclosure at call start
Every call begins with an automatic notice that the patient is speaking to an AI assistant — in the spirit of transparency.
AES-256 encryption
All patient data is encrypted in transit and at rest — bank-grade security.
EU data centre
Data is stored exclusively on EU-based servers (Hetzner) — it never leaves the EU.
Data minimisation
Only data strictly required for booking is collected: name, phone number and appointment time.
Call recording and transcripts
Every call can be recorded and automatically transcribed. You can search the transcripts and replay the recordings — all from the admin dashboard.
Automatic transcripts
Every call is transcribed and searchable by keyword, patient name or date.
Replay
Call recordings can be replayed from the admin dashboard — useful for quality assurance or disputed cases.
Consent-based recording
Calls are recorded only with patient consent — the system requests it automatically.
Details
Security and compliance: trust from day one
In a healthcare setting, handling patient data is not an afterthought. MediVox is built for full GDPR compliance from the start, and backs trust with both technical and organizational measures.
What it means in practice
- AI disclosure at the start of the call — the patient knows they’re speaking with an automated assistant
- Data minimization — we ask for and store only what the booking needs
- AES-256 encryption for stored data
- EU data center (Hetzner) — data does not leave the EU
- Data Processing Agreement (DPA) with every provider
- Support for deletion and export rights
Recording and transparency
Call handling is transparent and documented; recording and transcription follow what’s described in the privacy policy. The goal is that a practice can show, at any time, exactly where and how it handles patient calls — which is the foundation for taking automation seriously.
Modules
Explore the other modules
Solutions
See it by industry
Dental practices
Never miss another call at your dental practice
Medical practices
Automate your phone bookings — focus on patients
Veterinary clinics
Automated appointment booking for pet owners
Diagnostic centers
Simpler appointment booking for lab and imaging exams
Ophthalmology clinics
Automate ophthalmology bookings and patient communication
Dermatology
Automated booking for dermatology exams and treatments
FAQ
Frequently asked questions
Can't find what you're looking for? Send us a message and we'll get back to you shortly.
AI disclosure at call start, data minimisation, AES-256 encryption, EU data centre (Hetzner), full support for deletion and export rights, and a Data Processing Agreement (DPA) with every provider.
Exclusively in an EU data centre (Hetzner, Germany). Data never leaves the EU.
No, call recording is optional and only happens with patient consent. The feature can be toggled on or off in the admin dashboard.
Yes, the GDPR right to erasure (right to be forgotten) is fully supported. Patients can request deletion of their data, and the system executes it.
Yes, we have signed DPAs with every provider, and we provide a DPA to our customers as well.
Your front desk can finally focus on patients — leave the phone to MediVox.
Two steps, and our team will call you back within 24 hours.
We onboard a limited number of practices each month to keep every rollout white-glove.