Anamnesix Română

Legal documents

Sub-processors

Version 24 September 2026 · Processor: Lava Labs SRL

About this list

Lava Labs SRL uses the companies below to run Anamnesix. Each one processes some data on our behalf. This list forms Annex III of the Data Processing Agreement concluded with every doctor who creates an account, and it is also referenced by the Privacy Policy.

Two facts frame the whole list. First, every patient file, thumbnail, voice memo and database backup is encrypted on the doctor's phone before upload, with keys that never leave the phone, so the storage vendors only ever see ciphertext. Second, the only place where patient data is processed in readable form outside the phone is the dictation feature, where audio and the resulting transcript pass through our transcription vendor for the time needed to return the text.

Everything patient-related is stored and processed in the European Union. Where a vendor's parent company is established in the United States, the transfer mechanism is stated below.

Supabase

  • Vendor: Supabase, Inc., with the project hosted in Ireland (region eu-west-1).
  • Location of processing: European Union, Ireland.
  • Data received: doctor account data (email address, user id, subscription state, usage counters, device id and locale, audit events); encrypted patient files, thumbnails, voice memos and database backups as ciphertext; the recovery envelope; audio and transcript in memory only while a dictation request is relayed.
  • Purpose: authentication by email code, database, private file storage (bucket vault), serverless functions that meter usage and relay dictation.
  • Transfer mechanism: data is stored in the EU. For any remote access by the vendor's staff outside the EU: [TODO: confirm DPF certification or SCCs].

Soniox

  • Vendor: Soniox, Inc., using its European endpoint api.eu.soniox.com.
  • Location of processing: European Union.
  • Data received: the audio of a voice memo the doctor submits for dictation, the resulting transcript, and a reference made of the doctor's user id and a session id.
  • Purpose: speech-to-text transcription of voice memos in Romanian.
  • Retention: the audio file and the transcription are deleted by our systems as soon as the app confirms it has received the text, or within a day by a reconciliation job if the confirmation never arrives.
  • Transfer mechanism: EU endpoint pinned in code. For the US parent entity: [TODO: confirm DPF certification or SCCs].

Sentry

  • Vendor: Functional Software, Inc. (Sentry), using its European Union data region.
  • Location of processing: European Union.
  • Data received: crash and error reports from the app. Before leaving the phone, reports pass through a scrubber that removes request data, reduces the user to an anonymous id, redacts email addresses, dates and digit sequences, drops navigation and console breadcrumbs, and never includes screenshots, note titles, note bodies or clinical sections.
  • Purpose: detecting and fixing defects.
  • Transfer mechanism: EU data region. For the US entity: [TODO: confirm DPF certification or SCCs].

PostHog

  • Vendor: PostHog, Inc., using its European Union host eu.i.posthog.com.
  • Location of processing: European Union.
  • Data received: anonymous product analytics events, only when the doctor has switched on usage statistics. Events name screens and features, never patient data, and no email or identity is attached. Session replay, geolocation and surveys are disabled.
  • Purpose: understanding which features are used.
  • Transfer mechanism: EU host. For the US entity: [TODO: confirm DPF certification or SCCs].

RevenueCat

  • Vendor: RevenueCat, Inc.
  • Location of processing: United States.
  • Data received: the Supabase user id of the doctor and the purchase and subscription state reported by Apple or Google. No email address, no name, no patient data.
  • Purpose: managing Premium subscriptions and transcription top-ups, and notifying our server of purchase events.
  • Transfer mechanism: [TODO: confirm DPF certification or SCCs].

Brevo

  • Vendor: Sendinblue SAS (Brevo), established in France.
  • Location of processing: European Union.
  • Data received: the doctor's email address, the sign-in code, and the text of subscription lapse notices.
  • Purpose: sending sign-in codes and account notices.
  • Transfer mechanism: none required, EU vendor.

Apple and Google

  • Vendors: Apple Distribution International Ltd. and Google Ireland Ltd., as operators of the App Store and Google Play.
  • Location of processing: European Union and worldwide, under the vendors' own terms.
  • Data received: purchase and receipt data for subscriptions and top-ups, under the doctor's own store account. No patient data.
  • Purpose: billing, receipt validation, app distribution.
  • Transfer mechanism: the vendors act as independent controllers for store purchases under their own legal terms.

Expo (EAS)

  • Vendor: 650 Industries, Inc. (Expo).
  • Location of processing: United States.
  • Data received: source code and build artefacts of the app during builds. No doctor or patient data.
  • Purpose: building and signing the app binaries.
  • Transfer mechanism: not applicable, no personal data of doctors or patients is processed.

Notice of changes

Before adding or replacing a vendor that processes patient data or doctor account data, Lava Labs SRL emails every account holder at least 30 days in advance. The email names the vendor, the data concerned, the location and the transfer mechanism. A doctor who objects and cannot reach an agreement with us may delete the account without penalty before the change takes effect, as described in the Data Processing Agreement.

Removing a vendor or narrowing the data it receives does not require notice; it is recorded in the change log below.

Change log

  • 2026-09-24: first published version. Vendors: Supabase, Soniox, Sentry, PostHog, RevenueCat, Brevo, Apple, Google, Expo. Resend is no longer used for email.