Data Processing & Security
Clients trust Autoscriber with their data so that they can focus on the work that matters most within healthcare. That’s why we are focused not only on creating automation, but also on implementing robust safeguards to keep our customers’ data safe.
This article is focussed on giving an overview of the processes and standards that Autoscriber has in place to ensure the utmost security and our customers data is safe.
Summary:
Autoscriber is fully GDPR compliant and our processes have been checked by our legal counsel. Accordingly,
- All data is stored in EU data centres,
- Patients and other stakeholders can access our privacy statement and data processing addendum at Privacy Policy that clearly explains how their data are being used,
- Data are stored only as long as needed or removed (within the integrated version),
- Data retention policy is applicable, where data is deleted within 48 hours after a data deletion request is made,
- Autoscriber has ISO 27001 Certification and NEN 7510 Certification.
Security Measures Taken by Autoscriber:
- Access Control: The access to the Personal Data is restricted to the authorised employees on a need-to-know basis.
- Employee verification: Every employee (even interns) are required to present a VOG (or police clearance) certificate and identification card.
- Encryption: Personal Data is always encrypted at rest and in-transit (SSL connections are used).
- Multi-factor Authentication: The access to the Personal Data is secured with two-factor authentication (2FA)
- Pentesting: Our system's security is being tested by an external auditor at least once a year.
- Non-disclosure: Non-Disclosure Agreements (NDA’s) are concluded in the event that confidential information is exchanged.
Our Security Certificates & Standards
Autoscriber currently holds the following security certificates:
- ISO 27001, with an external audit conducted by Kiwa Netherlands. The certificate can be found here: ISO 27001 Certification
- NEN 7510, with an external audit conducted by Kiwa Netherlands. The certificate can be found here: NEN 7510 Certification
- GDPR Compliance, based on our Privacy Policy, found in this document here: GDPR Compliance
- EU AI Act, based on our compliance, found in this document here: EU AI Act Compliance
- C5, our cloud providers are C5 approved and have C5 attestations. More info found here: C5 Compliance
How We Protect Our Customers’ Data
The following describes the measures Autoscriber takes to ensure our customers’ data is protected:
- We adhere to strict data minimisation policies e.g. audio is not stored.
- We employ end-to-end encryption for data at rest and in transit.
- We conduct regular penetration testing and vulnerability assessments.
- We use secure cloud infrastructure through our partnerships with Microsoft Azure and Google Cloud.
- Our staff undergoes rigorous training in data processing.
Sub processors
We do not share data with any third parties and data is processed by sub processors only insofar as it is necessary for us to provide you with the service we offer.
We strive towards total transparency regarding your data, who processes your data and for what ends. Furthermore, we conduct regular supplier checks to ensure that our suppliers meet the minimum conditions according to ISO and other standard requirements. Please see our Data Processing Addendum for a detailed overview of our sub processors and their purpose.
Training our models
For Autoscriber to improve on services delivered, the training of models is necessary. We will, however, never use customer data without explicit consent. In case you would like us to use your data to finetune our models to your use case, we will conclude a separate data-processing agreement outside of our standard contract.
In short, unless you request otherwise, your data is never used to train our models and is never stored longer than you wish.
Cloud Security and Compliance
Autoscriber makes use of a combination of Azure and GCP, which each have their relevant security standards, which are described below.
Microsoft Azure Security and Compliance:
Azure's Compliance Portfolio:
Azure has one of the largest portfolios of compliance certifications, including key data privacy and security certifications such as ISO/IEC 27001, ISO/IEC 27018, CSA STAR, and most importantly, General Data Protection Regulation (GDPR) compliance. This provides legal assurance that the data protection principles set forth in the GDPR are being followed.
Data encryption and protection:
Azure encrypts data both at rest and in transit using industry-standard encryption techniques (AES-256 for data at rest and TLS for data in transit). This ensures that even if data is not pseudonymised, it remains secure through layers of encryption and protected from unauthorised access.
Azure Security Controls:
The platform includes Azure Security Center, which provides advanced threat detection, security monitoring, and automated remediation capabilities. These tools help continuously monitor and secure data processing environments, ensuring protection against emerging threats.
Google Cloud Platform (GCP) Security and Compliance:
GCP's Compliance Standards:
GCP is also certified against key international standards such as ISO/IEC 27001, ISO/IEC 27018, SOC 1/2/3 and is fully GDPR compliant. GCP offers tools and services such as Cloud Data Loss Prevention (DLP) to ensure sensitive data is handled securely.
Encryption as Standard:
Like Azure, GCP encrypts data in transit and at rest with robust encryption technologies. Data stored on Google Cloud is protected by industry-leading encryption algorithms (AES-256), and all communications between Google services and between data centers are encrypted with Transport Layer Security (TLS).
Data Sovereignty and Privacy Control:
GCP provides granular control over where data is stored geographically (within the EU or other regions), ensuring compliance with GDPR data storage requirements. Google also maintains advanced logging and audit trails, allowing companies to monitor access and activity on their data.
How we ensure secure data processing even without pseudonymisation:
- Strong data encryption: Encryption is a core part of our security strategy and provides a strong level of protection. With encryption at rest and in transit, sensitive data remains unreadable to unauthorised parties, even in the event of a data breach. This provides a significant layer of protection for personal data.
- Data at rest: Both Azure and GCP encrypt all data at rest by default. This means that even if a storage medium is compromised, the data remains unreadable without the associated decryption keys, which are strictly managed with access controls.
- Data in transit: Data transferred between Autoscriber systems and external systems or between cloud services is encrypted using strong cryptographic protocols (TLS 1.2 or later), which protects against man-in-the-middle attacks.
- Access Control and Monitoring: Both Azure and GCP implement role-based access control (RBAC), which ensures that only authorised individuals can access specific data based on the principle of least privilege. Access logs and auditing mechanisms provide a comprehensive view of who has accessed or modified data, ensuring traceability and accountability.
- Identity and Access Management (IAM): We use IAM features across both platforms to tightly control who has access to sensitive data. Access is limited to those who need it for their role, and access requests are continuously logged and audited.
- Monitoring and Threat Detection: Both platforms offer advanced monitoring tools such as Azure Monitor and Google Cloud Security Command Center. These systems use machine learning to detect anomalies or potential threats in real time, enabling proactive defense against security incidents.
- Data residency and local data storage: For companies operating in Europe or needing to comply with the GDPR, where data is stored plays an important role. Both Azure and GCP offer the ability to store data within specific geographic regions or countries, ensuring strict compliance with data localization requirements under the GDPR (such as the requirement to keep EU citizen data within the EU).
Why these guarantees are sufficient:
Although in certain cases data is not pseudonymised, the combination of encryption, access control, monitoring and compliance certifications provides a high level of assurance that personal data is processed securely and in accordance with the GDPR.
Data protection by design and default:
Both cloud providers implement Data Protection by Design and Default, as required by GDPR Article 25. This means that Azure and GCP integrate data protection principles into their core infrastructure, ensuring that security is not an afterthought, but a primary consideration in all data processing activities.
Limiting data leaks:
In the unlikely event of a data breach, both Azure and GCP have robust incident response processes and tools to quickly detect, analyze, and contain breaches. With encryption and access controls, even in the event of a breach, exposure of personal data is minimised, significantly reducing the risk to data subjects.
Legal guarantees and processing agreements:
Both Microsoft and Google offer legally binding data processing agreements (DPAs) that meet GDPR requirements. These agreements define the roles of data controllers and processors, which ensures that data is handled in accordance with GDPR standards. In addition, these companies ensure that data subject rights, such as the right to access, rectify or delete personal data, are respected.