Trust & security
Swiss hosting. Clear control over every call.
Persistent application data stays in Switzerland. Your clinic controls who can see call data, how long it is kept, when calls are forwarded, and how much forwarded traffic Vite Clinic answers.
Last reviewed: 27 July 2026
Swiss control
Your clinic stays in control
The clinic stays in control of patient calls while Vite Clinic provides the service under the clinic’s instructions.
- The clinic is normally the controller for patient calls and decides why and how call data is used.
- Vite Clinic acts as processor for patient-call data on the clinic’s documented instructions.
- Benjamin Crozat EI remains controller for accounts, billing, security, and direct business administration.
Swiss control
Clinic data serves the clinic
Vite Clinic does not sell call data, use it for advertising, or train its own models on it.
- Vite Clinic does not sell call data, use it for advertising, or train its own models on it.
- Vite Clinic makes no automated medical diagnosis or triage and no other legally significant decision.
- Clinic call content is used only to provide, secure, and support the configured service.
Clinic control
Clinic-controlled activation
We configure Vite Clinic from clinic-approved information, test the human path, and let the clinic set how much forwarded patient traffic Vite Clinic answers.
Swiss control
Providers
Persistent application data is hosted in Switzerland. Twilio carries live calls and OpenAI powers the assistant; they process only the call data needed for those roles. Open each provider for the full details.
Infomaniak Network SA Switzerland
- Role
- Application hosting, persistent database storage, and encrypted off-server backups.
- Provider retention
- Service-specific. Its DPA provides for deletion after an applicable instruction or service end; the exact production backup window must be recorded before launch.
- Subprocessors and dependencies
- Service-specific sub-processors may be added with advance notice and an objection period.
- Swiss transfer safeguards
- Swiss processing agreement, confidentiality, least-privilege access, and a production service register.
- Current position
- Swiss application hosting is implemented; the selected production services, backup window, and access list still require launch evidence.
Twilio Ireland Limited Ireland, United States, and carrier countries
- Role
- Swiss phone number, call routing, and live audio transport. Call metadata and audio pass through Twilio for the service to work.
- Provider retention
- Twilio Call resources are directly retrievable for 13 months. Older records can remain available through Bulk Export or Log Archives, while listed phone-number fields have a maximum time to live of 120 days. Vite Clinic does not enable Twilio call recording, but Twilio still carries live audio to operate the call.
- Subprocessors and dependencies
- Twilio Inc., AWS, ClickHouse, and account- or number-specific telecommunications carriers; optional speech providers only if enabled.
- Swiss transfer safeguards
- Twilio DPA, Binding Corporate Rules, adequacy decisions, the Data Privacy Framework, and Swiss-adapted SCCs as applicable.
- Current position
- European routing is available in Dublin, but the regional account, credentials, phone routing, carrier path, and a test call still require verification. Until then, calls use the disclosed United States route.
OpenAI Ireland Ltd. Europe when verified; otherwise global processing
- Role
- Realtime speech and assistant processing. Audio and conversation content are processed to answer the call.
- Provider retention
- API data is not used for model training unless the customer opts in. Default abuse-monitoring logs may retain content for up to 30 days; approved reduced-retention controls change that posture.
- Subprocessors and dependencies
- The current API list includes Microsoft, CoreWeave, Oracle Cloud, Google Cloud, AWS, Cloudflare, Snowflake, Confluent, Cerebras, and listed support providers; participation depends on features and controls.
- Swiss transfer safeguards
- OpenAI DPA, adequacy decisions and SCCs. These contractual safeguards do not by themselves resolve Swiss professional secrecy.
- Current position
- European processing is supported, but it is not treated as active until the provider account, contract amendment, eligible models, endpoint settings, disabled tracing, and reduced-retention controls are verified.
Swiss control
Retention
Vite Clinic applies the following default retention periods. The clinic agreement may require shorter periods.
- Vite Clinic does not intentionally store raw call audio. Transcripts, caller identifiers, health-related free text, and handoff payloads are scrubbed after 30 days.
- The reduced operational call record is deleted after 365 days. Audit records use 365 days; application logs default to 14 days.
- Billing and accounting records follow their separate legal purpose. Encrypted backups expire on a documented schedule.
Clinic control
Ready for clinic use
Before patient calls begin, we confirm the DPA, caller notice, human alternative, retention schedule, provider register, and professional-secrecy review with the clinic.
Controls in the product
Vite Clinic includes the operational controls a clinic needs to start with confidence.
- HTTPS for the public site, application, and service APIs.
- Named organization memberships and clinic assignments control customer access.
- Audit records for sensitive account and clinic actions.
- Encrypted backups, signed deployments, and a documented rollback path.
- Operational logs designed to avoid call content and patient details.
- Documented incident response and assistance with the clinic’s DPA, DPIA, and data-rights duties.
Security review
Review the evidence
Request the security pack for the documents your clinic needs to review Vite Clinic with confidence.
Trust review for your clinic
Review the full data path with us.
Book a focused review of Swiss hosting, live-call providers, retention, access, and the evidence your clinic needs.