About this document
This annex supplements the Privacy policy and the data processing agreement between UAB Vocali (the Processor) and the Controller. It sets out the information a controller is entitled to under Article 28(2) and Article 32 of the GDPR:
- which sub-processors we engage, what functions they perform, and where they process data;
- which technical and organisational security measures we apply.
The document is intended for controllers — healthcare institutions and self-subscribing clinicians — and their data protection officers.
01 Subject-matter of the processing and the parties' roles
This section is structured to follow the elements listed in Article 28(3) of the GDPR.
Subject-matter of the processing. Transcribing the audio recording of a patient visit, de-identifying the transcription, producing a structured medical document, processing the guided-onboarding test recording and collecting related technical metadata.
Nature and purpose of the processing. Automated processing whose sole purpose is to produce a medical document for the Controller, introduce the User to Vocali's main functions, assess microphone and speech-recognition quality and keep the Services running. The data is not processed for any independent purpose of the Processor.
Duration of the processing. For as long as the service agreement or the subscription is in force. Retention periods for individual data are set by the Controller, except for the specific periods expressly stated for particular data categories in the Privacy policy.
Types of personal data. Special category (health) data contained in the audio recording, the transcription and the document content; user account data; the User's voice recorded during guided onboarding, the masked onboarding transcription and the content of the test form; technical metadata.
Categories of data subjects. Patients and users of the Vocali platform.
The parties' roles. The Controller is the healthcare institution or the self-subscribing clinician. The Processor is UAB Vocali. The service providers listed below are sub-processors.
02 Sub-processors
| Sub-processor | Function | Place of processing |
|---|---|---|
| Google Cloud | Speech recognition (STT), the generative AI service used to produce document content, temporary storage of processing files and the onboarding test recording, and processing-status notifications | European Union (several EU regions) |
| Amazon Web Services (AWS) | Application runtime, database, backups, password management, website hosting | European Union (Germany) |
| Sentry | Error and performance monitoring in the browser: error reports, browser and device details, IP address, technical recordings of a share of sessions | European Union (Germany) |
| Resend | Transactional email: invitations, password resets, sign-in verification codes, invoices | EU and US; no patient visit data is transferred |
| Stripe | Self-serve subscription payments and invoicing (individual practice model only) | EU; no patient visit data is transferred |
A data processing agreement is in place with each sub-processor, providing that data is processed only on our instructions, is not used to train artificial intelligence models or for any other secondary purpose, and that any sub-contractors the provider engages are bound by the same obligations.
Transfers outside the EEA
Patient visit data — the audio recording, the transcription and the document content — and guided onboarding data are processed only within the European Union.
The transactional email and payment providers belong to international groups, so in individual cases (for example during technical support) a transfer outside the EEA is possible. Where that happens, standard contractual clauses approved by the European Commission, or an adequacy decision, apply. These providers have no access to patient visit data.
Changes
We notify the Controller in advance, by email or through the platform's notification tools, of any intended engagement of a new sub-processor or change of an existing one. The Controller has the right to object to a change on reasonable grounds.
03 Technical and organisational measures
Access control
- Access to the processing environment, storage, databases and AI services is limited to pre-authorised Processor engineers and administrators, signing in with individual credentials.
- Two-factor authentication (2FA) applies — both to internal access and to user sign-in to the platform.
- Access rights are managed on the principle of least privilege and reviewed when responsibilities change.
- Internal passwords and credentials are held in a password management service, and database credentials are rotated automatically.
- All sign-ins and significant actions are recorded in audit logs.
User authentication in the platform
- Password complexity requirements apply, and passwords are stored only in cryptographically hashed form.
- Sign-in additionally requires a verification code sent by email; once entered successfully, the same browser is not asked for a code again for up to 14 days.
- Repeated failed sign-in attempts are rate-limited by username and by IP address.
Network and encryption
- All transfer of data between the browser, the processing environment and sub-processors uses TLS.
- Data is encrypted at rest using AES-256.
- Production, development and test environments are separated; real patient visit data is never used for testing.
Clean-up of temporary files
- Intermediate files created during processing (audio fragments, intermediate speech recognition output) are deleted as soon as processing completes.
- For interrupted sessions, where the normal clean-up does not run, a scheduled fallback applies: temporary file storage areas are cleared at least once every 24 hours, and local temporary files no later than 24 hours after they were created.
- De-identification takes place in our own environment before the text is passed to the generative AI service.
Guided onboarding
- Guided onboarding is an optional test feature in which the User reads a prepared scenario. Before recording begins, the User is clearly warned not to record a real patient consultation or any patient data.
- The onboarding audio recording is held in the European Union for no longer than 3 days and is then deleted automatically.
- The unmasked onboarding transcription is used only during processing and is not retained. The masked transcription is kept until the User's account is deleted, unless the User or the Controller requests its earlier deletion.
- The test form generated during onboarding is subject to the Controller's selected retention period for generated documents.
- Guided onboarding data is not used to train or improve artificial intelligence models.
Error monitoring
- Error and performance monitoring data is processed in the European Union.
- The following measures apply to technical session recordings: all text content is masked, images and audio are not recorded, and sensitive parameters are stripped from URLs (the authentication token and the patient identifier passed in from the institution's information system).
- Technical session recordings are made for only a share of sessions and are used solely to diagnose errors.
Backups
- Automated database backups are held for 7 days in the European Union, then deleted automatically and irreversibly.
- Audio recordings never enter backups. Generated documents and de-identified transcriptions do, for as long as they are retained under the applicable period.
Incident management
- The Controller is informed of a personal data breach without delay, and no later than 24 hours from the moment it is identified.
- The Processor provides information and cooperates so that the duty to notify the State Data Protection Inspectorate and/or the data subjects is discharged.
04 The Controller's rights
- Assistance with data subject rights. On receiving a data subject request, we forward it to the Controller without delay and provide the information and technical means needed to fulfil it.
- Audit. The Controller has the right, on reasonable prior arrangement, to obtain the information needed to verify compliance with this annex.
- Return and deletion of data. On termination of the Services, data is provided to the Controller or deleted, at the Controller's choice. Deletion is carried out in the platform without delay, and in backups no later than within 7 days.
- Retention periods. Retention periods are set by the Controller; how this works in practice is described in the "Retention periods" section of the Privacy policy.
05 Contact
For questions about this annex, our sub-processors or our security measures, email hello@vocali.lt.