The GDPR-Compliant Video Conferencing API for Telehealth
Trusted by leaders in telemedicine
KVB-certified Consularia GmbH, a leading German telemedicine provider, powers its platform with Digital Samba Embedded.
“Digital Samba as a company has an understanding of the customer's vision, which is a rare trait, and goes above and beyond to accommodate our difficult requirements.”
Sebastian Gerhard
CIO & Co-Founder
Keep the call on your platform
Test the embedded experience right on this page - no redirects, no detours.
Please wait until we set up your room
Other European providers who put their trust in Digital Samba
Minimal code, maximum safeguards
A prebuilt, accessible video room inside your own app – then control layout, recording, captions and roles with the SDK.
npm install @digitalsamba/embedded-sdk
import DigitalSambaEmbedded from '@digitalsamba/embedded-sdk';
const sambaFrame = DigitalSambaEmbedded.createControl({ url: YOUR_ROOM_URL });
sambaFrame.load();
Why telehealth teams choose Digital Samba
For any telehealth platform serving patients in the EU or UK, the video layer is not just a feature choice – it is a decision about processing special-category health data under GDPR Article 9. Digital Samba is the video conferencing API built for exactly that: EU-built and EU-hosted, fully GDPR-compliant, completely white-label, with no application or session data stored outside the EU/EEA and real human integration support.
True EU data sovereignty
EU-built and EU-hosted from day one, on infrastructure owned and operated by European companies. No application or session data leaves the EU/EEA. For EU and UK telehealth, that is your data-residency answer built in, not a configuration you have to police.
Fully white-label and embedded
Drop the video room straight into your telehealth platform, patient portal or EHR front end via an iframe and the JavaScript SDK. Your brand, your domain, your clinical workflow – patients never see the words "Digital Samba".
Low-code, prebuilt, fast
A prebuilt, accessible video room you embed in days – not a media stack you assemble over months. Adaptive quality, mobile and desktop, and automatic reconnection are handled for you, with around 60 SDK methods when you need deeper control.
Privacy by design
A DPA with clear Controller and Processor roles, optional end-to-end encryption for sensitive consultations, encryption in transit and at rest, and no tracking or ad pixels. Built to help you meet your GDPR Article 9 obligations.
Clinical features out of the box
Waiting rooms, role-based access, cloud recording with bookmarks, screen share, whiteboard, breakout rooms, Q&A, and optional AI captions, transcripts and summaries – ready to switch on, with nothing extra to build.
Human support, built for the long run
A European company with 20+ years behind it, real human integration support, an open roadmap and no vendor lock-in. Connects to your EHR/EMR, scheduling and billing systems through the API, SDK and webhooks.
Secure video that wins trust
Real-world quotes on compliance, performance, and human support.
What EU telehealth video has to get right
Health data is one of Europe's most tightly regulated categories. A telehealth video API has to cover several things at once – here is how Digital Samba is built for each.
Special-category data (GDPR Article 9):
Health data needs a lawful basis beyond Article 6, plus an Article 28 DPA. Digital Samba is your processor under a DPA, with control over recording, retention and deletion.
EU data residency
All application and session data stays in the EU/EEA – hosted in the Netherlands and across the EU, backups in Germany, on European-owned infrastructure, not "EU region" options on US clouds.
Confidentiality
Encryption in transit (TLS, DTLS-SRTP) and at rest (AES-256-GCM), plus optional end-to-end encryption so only participants – not Digital Samba – can access the consultation.
Access control
Only the right people should be in a consultation. Waiting rooms and role-based access let you admit patients individually and control what each participant can see and do.
EU AI Act
Participants must be told when AI is in use. Digital Samba's AI captions, transcripts and summaries are optional and fully under your control.
European Health Data Space (Regulation (EU) 2025/327)
Telemedicine is moving into a common EU framework this decade – EU-hosted, GDPR-first infrastructure keeps you aligned with where the rules are heading.
We check all the boxes for telehealth
Built in Europe, privacy-first by design - ready for real clinical workflows.
FAQ
Yes. Video consultations involve special-category data under GDPR Article 9, so Digital Samba operates as your processor under an Article 28 data processing agreement, keeps all session and application data inside the EU/EEA, and gives you control over recording, retention and deletion. You remain the controller and set the lawful basis for each use.
All application and session data is stored inside the EU/EEA – production in the Netherlands and across the EU, with backups in Germany, on infrastructure owned and operated by European companies. No session or application data is stored outside the EU/EEA. On-premises deployment offers the strongest single-country residency guarantees.
Digital Samba's standard EU service is built for GDPR and EU data residency and is not operated under a HIPAA Business Associate Agreement (BAA). Customers with HIPAA obligations have two options: US-based infrastructure hosted with a HIPAA-eligible provider, or an on-premises deployment, which gives you full control of the environment and lets you execute a BAA with your own infrastructure provider. For EU and UK telehealth, GDPR and EU data residency are usually the relevant requirement – contact us to discuss HIPAA deployment options.
Yes. Digital Samba is fully white-label. You embed the video room in your own platform, patient portal or EHR front end via an iframe and the JavaScript SDK, under your own brand and domain, and connect it to scheduling, billing and records through the API and webhooks.
Yes, optionally. With end-to-end encryption (AES-256-GCM), only the session participants can decrypt audio, video, screen share, chat and whiteboard content. Note that end-to-end encryption and server-side features such as cloud recording and transcription are mutually exclusive by design, so you enable it for the sessions that need maximum confidentiality.
Digital Samba's AI captions, transcripts and summaries are optional and under your control. From 2 August 2026 the EU AI Act requires you to inform participants when AI is in use; because the features are switchable per room, you can turn them on only where you have a lawful basis and have met your transparency obligations.
Those are powerful video APIs where you typically build the interface, recording and compliance yourself, often on US-headquartered infrastructure. Digital Samba is a managed, EU-hosted embedded API: you get a prebuilt, white-label room and GDPR-by-design compliance in days, with all data kept in the EU/EEA.
Let's start your integration today
Get in touch and run us through your use case.