Security and privacy

Sub-processor list: version of 29 September 2026 (2026-09-29)

Summary

All patient data is processed and hosted in the European Union.

  • No photo, analysis or simulation is transferred outside the European Union.
  • Hosting: OVHcloud, server located in Strasbourg (France). AI analysis: Scaleway, Paris (France). Visual simulation: IONOS Cloud (Germany).
  • Database and temporary files in an encrypted volume (LUKS2, AES-256), with the key kept off the server.
  • Photos deleted no later than 30 days after capture; never used to train models.
  • Payments: Stripe receives no patient data.

1. Where the data is processed

List of the sub-processors involved in the service. Statements about retention and training by the AI providers reflect their own contractual statements.

Sub-processor and entityCountry of processingRole and dataSafeguardsSince
OVHcloudOVH SAS, 2 rue Kellermann, 59100 Roubaix, FranceFrance (Strasbourg)Hosting of the application server and database (VPS)All service data, stored in an encrypted volume (LUKS2, AES-256)OVHcloud Data Processing Agreement incorporated in the terms of serviceProvider's data processing agreement17 July 2026
Scaleway — Generative APIsScaleway SAS, 8 rue de la Ville l'Évêque, 75008 Paris, FranceFrance (Paris)Analysis of the photo by an AI model (Mistral Small 3.2; fallback Mistral Medium 3.5, same provider, same region)Face photo and analysis instructions, for the duration of processing; the provider states it does not store requests (except abuse or server errors, up to 2 weeks) and does not use them for trainingScaleway data processing agreement (DPA) incorporated in the contract; no retention of requests and no training (provider statement)Provider's data processing agreement28 September 2026
IONOS Cloud — AI Model HubIONOS Cloud (IONOS group entity named in the contract); inference in IONOS Cloud data centres in GermanyBeing activated — the simulation is unavailable until this service is active; there is no fallback engine outside the European Union.GermanyRendering of the visual simulation (FLUX.2 [klein] 4B model); the treated area is then recomposed onto the original photo on our server in FranceFace photo, for the duration of rendering; the provider states inputs are neither logged nor stored and not used for trainingIONOS Cloud data processing agreement incorporated in the contract; inputs not logged, not stored, not used for training (provider statement)Provider's data processing agreement28 September 2026
Scaleway — Transactional EmailScaleway SAS, 8 rue de la Ville l'Évêque, 75008 Paris, FranceFrance (Paris)Delivery of transactional e-mails (confirmation, appointment, quote)Recipient name and e-mail address, message content; never any face imageScaleway data processing agreement (DPA) incorporated in the contractProvider's data processing agreement28 September 2026
StripeStripe Payments Europe, Ltd., Dublin, IrlandeIreland (EU)Payment of the clinic's subscriptionClinic billing data only — no patient dataStripe Data Processing Agreement; receives no patient dataProvider's data processing agreement1 May 2026

E-mail correspondence

Messages sent to contact@phimetra.com and privacy@phimetra.com go through Cloudflare Email Routing and are read in a Google (Gmail) mailbox. This channel is not used to process photos: do not attach any photo.

2. List version and notice

Current version: 2026-09-29

Any addition or replacement of a sub-processor is announced to the client with 30 days’ notice, so that the client can object. The list is versioned and dated on this page.

Change history

  • 29 September 2026 — Earlier simulations stored at fal.ai have been deleted (478 requests, 369 files). No sub-processor added. Clarifications: IONOS Cloud entity named in the contract; link to the contracts of OVHcloud (OVH SAS).
  • 28 September 2026 — All processing of patient data moves into the European Union: analysis from OpenRouter (United States) to Scaleway (Paris), simulation from fal.ai (United States) to IONOS Cloud (Germany), e-mails from Resend (United States) to Scaleway (Paris). Free fallback AI models are removed. The site is no longer relayed by the Cloudflare proxy.

3. Technical and organisational measures

  • Encryption in transit: TLS (HTTPS) between the browser and the server, and to each sub-processor.
  • Encryption at rest: the database (photos, analyses, appointments, log) and temporary simulation files are stored in a LUKS2 encrypted volume (AES-256-XTS, argon2id key derivation). The key is not stored on the server: it is kept in Scaleway Secret Manager (Paris) and only read at start-up, in memory.
  • Backups: made inside this encrypted volume; off-server copies are encrypted (AES-256).
  • Access log: every read, listing, export, creation, modification, deletion or sharing of a patient record through the application is recorded (who: account identifier or “patient / anonymous”; when; what: data type and identifiers; route; outcome; a hash of the IP address, never the address in clear). The log is kept for 12 months and can be consulted by the publisher; an extract is provided to the clinic on request for its own records. Administrator access to the database is also logged by the database (query logs).
  • Restricted access: a single person (the publisher) has administrator access to production; server access by SSH key only.
  • No face image is ever sent by e-mail.
  • The Meta advertising pixel never loads on the pages of the patient journey; on marketing pages it only loads after consent.
  • The face-detection models used in the browser (MediaPipe) are served by phimetra.com: no call to Google during capture.

Limitations: there is no end-to-end encryption. Encryption at rest protects against access to the disks and copies; it does not protect a compromised server while it is running.

4. Retention and automatic deletion

  • Face photos (and the derived face signature): deleted no later than 30 days after capture.
  • Temporary simulation files: erased as soon as the result has been read, and no later than 2 hours afterwards.
  • Analyses, appointments, simulation sessions, quotes, invitations and the access log: deleted 12 months after creation.
  • Deletion jobs run every night on the server.

5. No model training

Photos and results are never used to train models, neither by Phimetra nor by its AI sub-processors: Scaleway and IONOS state this in their terms.

6. Data breach

Phimetra notifies the client of any personal data breach within 48 hours of becoming aware of it.

7. Data subject rights and impact assessment

The clinic is the controller; Phimetra acts as processor. Phimetra assists the clinic in responding to requests to exercise rights (access, rectification, erasure, restriction, portability, objection) and with its data protection impact assessment (DPIA): a DPIA file can be downloaded below. At the end of the contract, the data is deleted and a written certificate is provided.

8. EU Artificial Intelligence Act

Phimetra is a limited-risk AI system within the meaning of Article 50 of Regulation (EU) 2024/1689: the user is informed that the results are produced by an AI system. Phimetra is not a medical device and does not produce any diagnosis.

9. What Phimetra does not have

  • No HDS, ISO 27001 or SOC 2 certification.
  • No external security audit.
  • No designated data protection officer (DPO); the dedicated contact is privacy@phimetra.com.
  • No end-to-end encryption.

10. Downloadable documents

Versions of 29 September 2026, in PDF format.

11. Data protection contact

For any question about security or data: privacy@phimetra.com

Wahib Znidah, entrepreneur individuel (SAYWA) — SIREN 888 001 054 — 274 rue du Collège, 74950 Scionzier, France

See also

Security and privacy · Phimetra