Compliance · Trust & Security

Trust & Security

Dioscope is an educational platform composed of several modules. Most of them handle text only — courses, profiles, progress records, certifications, payments. One specific module, Voxi (dictation), is opt-in and captures audio in real time, automatically anonymising it before anything is persisted. This page documents how data flows in each case, which subprocessors are involved, and every user's rights under the GDPR.

Modules and the data they handle

The platform splits into two groups of features with distinct data flows:

Educational platform

Courses, interactive content, profiles, progress records, certifications, payments. Text only — no audio.

Subprocessors: LearnWorlds, Supabase.

Voxi (dictation) — opt-in

Optional voice-dictation module. Captures audio in real time, anonymises it automatically, and persists only de-identified text. Audio is never stored.

Additional subprocessor: Microsoft Azure (West Europe).

Data flow — Voxi (dictation)

This section describes the pipeline of the Voxi module only. The remaining features do not involve audio.

1. Capture
User device
Microphone → browser RAM. Never written to local disk.
2. Transit
TLS 1.3 gateway
Supabase Edge Function (EU). Memory-only passthrough, < 3 s.
3. Transcribe
Azure AI Speech
West Europe region. Audio discarded after response.
4. Anonymise
Azure PII + regex PT
NER + Portuguese rules: NIF, SNS, ID card, postal codes.
5. Persist
De-identified text
Encrypted at rest in Supabase (EU). Audio: zero retention.

Audio retention: zero. Audio bytes exist only in volatile memory of the gateway and the transcription service. They are never written to persistent storage on Dioscope, Supabase, or Azure infrastructure.

Subprocessors

Dioscope acts as data controller. The following subprocessors are engaged under Data Processing Agreements compliant with GDPR Art. 28. Microsoft Azure is engaged only when a user opts in to the Voxi module; the remaining subprocessors support the educational platform as a whole.

Subprocessor Role Region Certifications
Microsoft Azure AI Speech (transcription) and AI Language (PII detection) West Europe (Netherlands) ISO/IEC 27001 ISO/IEC 27017 ISO/IEC 27018 ISO/IEC 27701 ISO/IEC 22301 ISO/IEC 42001 SOC 2 Type 2 HIPAA HDS
Supabase Authentication, edge runtime, encrypted database West EU (Ireland) ISO/IEC 27001 SOC 2 Type 2 HIPAA
LearnWorlds Learning Management System (course delivery, certification) EU ISO/IEC 27001 SOC 2 GDPR

What data we process

Dioscope persists only the data strictly required to operate the educational platform: account information, course progress and certification records, and de-identified text after PII anonymisation. Audio and pre-anonymisation text never reach persistent storage.

Retention

Security controls

Your rights under GDPR

Every user has the rights granted by Articles 15–22 of the GDPR:

To exercise any right, write to suporte@dioscope.com. Response time: up to 30 days (GDPR Art. 12(3)).

Contact

For data protection, security incidents and general compliance: suporte@dioscope.com

First published: 7 May 2026
Version 1.0