1. Summary
- The data of practices and patients is hosted by Hetzner, in Germany (EU).
- The list below includes all suppliers that may process data on behalf of practices (Annex 2 to the Data Processing Agreement).
- Any new supplier is notified to practices 30 days in advance; the practice may object and terminate without penalty.
2. List of sub-processors
| Supplier | Data location | Purpose | What data | Safeguards |
|---|---|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Germany (Falkenstein) | hosting of servers, databases, files and backups; optionally, object storage | all data in the Service | data processing agreement under Article 28 GDPR; ISO/IEC 27001 certified data centres |
| Ploi B.V., Netherlands | Netherlands (the panel); the data remains at Hetzner | server administration: deployments, TLS certificates, processes | does not store the data; technical administrative access | data processing agreement under Article 28 GDPR |
| ASTINVEST COM SRL (SMSLink), tax ID (CUI) 9250710, Romania | Romania | SMS messages to patients: confirmations, reminders, links, authentication codes | phone number, SMS text, without medical data | contract with Article 28 GDPR clauses |
| Google Ireland Limited (Google Workspace), Dublin, Ireland | EU; possibly USA | transactional emails and PDF documents sent by email at the practice's request | email, name, message content, the attachment chosen by the practice | Cloud Data Processing Addendum; standard contractual clauses; EU–US Data Privacy Framework |
| Google Ireland Limited (Firebase Cloud Messaging), Dublin, Ireland | EU; possibly USA | push notifications in the MedAdmin Doctor and MedAdmin Pacient apps | device token, generic text without medical data | Firebase Data Processing and Security Terms; standard contractual clauses; EU–US Data Privacy Framework |
| Stripe Payments Europe, Limited, Dublin, Ireland | EU; possibly USA | patient payments to practices (Stripe Connect) | amount, description, reference; the card is entered by the patient directly with Stripe | Stripe Data Processing Agreement; standard contractual clauses; EU–US Data Privacy Framework |
| GitHub B.V. / GitHub, Inc. | EU / USA | source code, desktop application installers | none | listed for transparency |
3. Suppliers for the practice's data as a client of Sysqo
For the subscription payment, Stripe processes the practice's billing and payment data; here Sysqo Limited is the controller and Stripe is its processor. Card details never reach us.
4. Automated analyses and artificial intelligence
Automated imaging analyses run on our servers at Hetzner. We do not send images or patient data to artificial intelligence providers.
5. Suppliers currently inactive
They may be activated only after the 30-day notice: Sentry (error reporting, configured without personal data) and SmartBill (issuing Sysqo's invoices, only practices' billing data).
6. History
| Date | Change |
|---|---|
| 9 October 2026 | List updated: Amazon Web Services (S3, SES) and SmartBill, which are not used, were removed; Google Workspace, Firebase Cloud Messaging, Ploi and GitHub were added; Stripe also covers patient payments through Stripe Connect. |