SECURITY · INFRASTRUCTURE · COMPLIANCE
nexmin is a copilot that listens with you. To reduce the risks of that listening, the entire architecture starts from the sovereignty of the therapist and the consultant over their data.
What follows are the technical decisions that uphold that promise.
DATA · WHERE IT LIVES
Clinical data at rest stays in the European Union: the application server and the encrypted database with customer-managed keys live in Madrid. Queues and Gemini inference also remain within the EU; transcription uses an external provider under a specific transfer regime.
ENCRYPTION · ALL LEVELS
Encryption in transit (TLS 1.3) is taken for granted across the industry. nexmin adds a second layer of encryption inside the database itself, over the fields that may hold clinical material: audio, transcripts, notes, summaries, acoustic signals, hypotheses.
If one day an attacker reached the database, they would find unreadable text. And the encryption key lives separately from the storage, not alongside the data.
TRAINING · NOT USED FOR TRAINING
The AI that listens to your sessions is Gemini, on Google Cloud Vertex AI, contracted under the enterprise no-training tier. Neither the audio, nor the transcript, nor the clinical drafts are used to train public models. Neither Google’s. Nor ours.
Vertex AI processing is ephemeral: it reads and writes the draft without using it to train models. External transcription follows the safeguards described in its DPA.
ACCESS · TWO-FACTOR
nexmin supports standard two-factor authentication (TOTP), compatible with any authenticator app you already have installed — Google Authenticator, 1Password, Authy, Microsoft Authenticator.
The organization admin turns it on for themselves; each therapist enables it whenever they want from their profile. A sound habit, especially after an incident with your previous provider.
TRUST LOOP · YOUR SIGNATURE OVER EVERYTHING THE AI PROPOSES
This is the central doctrinal decision of nexmin: the AI proposes, you decide. Every draft generated by the officers — Scriba synthesis, process variables, voice analysis, Pensa, first-session extraction — reaches your screen as an editable proposal and may remain pending review. Until you approve, nothing becomes the canonical version in the consultant’s record.
And if you later unlock a closed note to review it, everything becomes editable again. Your human signature is always the canonical version.
TRACEABILITY · WHO ACCESSED WHAT
Every access to clinical information is recorded in immutable logs. If at any point you need to know who consulted what and when — because the consultant requested it, an incident, or an external audit — we provide the extract.
RETENTION · YOU DECIDE HOW MUCH TO KEEP
nexmin does not decide for you. The audio retention policy is configured per organization or per individual consultant, depending on the context.
COMPLIANCE · EUROPEAN LAW AS THE BASELINE
nexmin was born in Europe, with European regulation as the baseline of the architecture, not a checkbox at the end. The platform includes safeguards and compliance documentation, while your professional framework and applicable obligations still require your own review. It also includes an informed-consent template for AI recording, available as a starting point to adapt and review before giving it to the consultant.
NEED ANYTHING ELSE?
To request the signed DPA or go deeper into any specific architectural detail, write to hola@nexmin.ai.
The complete privacy policy, with the legal detail of data processing, lives at /privacidad.