# Ada Health

## Kurzbeschreibung
**"Health. Powered by Ada."**


Ada is an AI-powered symptom checker and digital health assistant for end users, as well as an enterprise platform for symptom intake, care navigation, clinical handovers, and insights. According to the terms, Ada uses a proprietary probabilistic reasoning technology built on a medically curated knowledge base; for partners, additional routing, integration, and handover functions are offered.

## Claim
Health. Powered by Ada

## Geeignet für
- Data Analysis
- Medicine & Healthcare

## Kernfunktionen
- Chatbot
- Medical Checkup
- Symptom Check

## Preismodell
- **free:** Free symptom checker for users with 24/7 access, AI-powered symptom assessment based on clinical evidence, a personalized assessment report, and the option to share relevant information with doctors. Ada explains that the assessment technology is available free of charge to people with smartphones and is offered without advertising.
- **other:** **Ada Assess / Enterprise** Enterprise solution for healthcare organizations, insurers, clinics, and digital care offerings. Includes intelligent symptom assessments, care navigation, clinical handover, insights, partner integration into websites, apps, or portals, simplified language, patient-friendly reports, SSO, and regular optimizations.


**Partnerships / Demo / individual contracts **According to the Help Center, Ada is financed through private investments, commercial relationships with healthcare systems, insurers, and life science companies, as well as grants and partnerships. Enterprise use apparently takes place individually via a demo/contact process; no public standard pricing was found.

## DSGVO und Datenschutz
**Gesamteinschätzung:** Conditional

**On-premises / local hosting: unclear**


An on-premises/local self-hosting option is not listed on the website.


**Private cloud / data center: partially**


There are clear indications of EU-based cloud infrastructure and separate storage of sensitive data within the EU. However, the website does not specify a dedicated, customer-isolated private cloud or single-tenant option.


**EU SaaS / Managed: Covered**


The website documents a provider-operated cloud solution with storage in the EU; health data and other sensitive data are always supposed to remain in the EU. This essentially confirms an EU SaaS/Managed option.


**Hybrid: Indirect / Not Available**


Ada describes website, app, and partner integrations as well as data flows to partner platforms, but a clearly documented hybrid architecture with an internal/local customer component and an external Ada component is not specified on the website.


**Service Agreement / DPA: Partially**


The privacy policy states that technical service providers act as data processors based on Data Processing Agreements pursuant to Art. 28 of the GDPR. However, an explicit DPA accessible to customers with Ada as the provider is not specified on the website.


**No Training: Partially**


The website does not clearly and generally state that prompts, uploads, chat histories, or outputs are never used to train general models. Instead, there are references to research and improvement, invitations to participate in research, and the use of anonymized data in the Terms; at the same time, health data is not shared with advertisers, and the rights to object and to erasure are described. A clear contractual “no training” exclusion is not specified on the website.


**Open Source / Transparency: Indirect / Not Available**


The website describes a proprietary AI/reasoning system. Open-source models, openly documented core components, or self-hostable open-source building blocks are not mentioned on the website.


**Data Processing**


Ada describes processing via its own services as well as through technical service providers. AWS EMEA and Google Commerce Limited EU cloud servers are listed as storage locations; a help page specifies Google Cloud in Belgium and MongoDB in the same EU data center. The service provider page lists, among others, AWS, GCP, MongoDB Atlas, Cloudflare, Confluent Cloud, Adjust, Braze, Honeycomb, Sumo Logic, Sentry, Copper, and Intercom. According to the privacy policy, limited data may be processed by subprocessors outside the EEA; health data and other sensitive data are always to remain within the EU.


**Conclusion**


For an EU/EEA directory, Ada can generally be classified as **conditionally** GDPR-compliant: The website provides substantial evidence of EU storage, GDPR compliance, data processing on behalf of clients, and security certifications. At the same time, key points required for a particularly stringent European assessment remain unaddressed or only partially substantiated, particularly freely available customer data processing agreements (DPAs)/DPAs, fully documented EU-only data paths without third-country involvement, as well as on-premises/self-hosting or a transparent “no training” path. There is much to be said for normal EU SaaS usage, but the website documentation is not robust enough to warrant an unqualified “yes” rating.


**Sources**


- [https://ada.com/privacy-policy/](https://ada.com/privacy-policy/)
- [https://ada.com/security/](https://ada.com/security/)
- [https://ada.com/help/how-is-my-data-stored-by-ada/](https://ada.com/help/how-is-my-data-stored-by-ada/)
- [https://ada.com/help/what-are-my-gdpr-privacy-rights/](https://ada.com/help/what-are-my-gdpr-privacy-rights/)
- [https://ada.com/service-providers/](https://ada.com/service-providers/)
- [https://ada.com/us/terms-and-conditions/](https://ada.com/us/terms-and-conditions/)

From the perspective of a user in the EU/EEA, there are several strong GDPR indicators on the website: Ada Health GmbH identifies itself as the controller pursuant to Art. 4(7) of the GDPR, describes the rights of data subjects, specifies processing based on Article 28 of the GDPR (data processing by a processor), stores personal data within the EU according to its privacy policy, and states that health data and other sensitive data always remain within the EU. At the same time, the website also lists subprocessors outside the EEA or U.S. providers and refers to third-country mechanisms. The website does not indicate a straightforward, fully documented EU-only operation without such restrictions, an explicitly published customer data processing agreement (DPA) available for download, or a clearly documented on-premises/self-hosting option. Therefore, GDPR-compliant use within the EU/EEA is plausible, but it is documented only *under certain conditions* and not comprehensively for all use cases.


**Positive**


The following are positively confirmed: a privacy policy with explicit reference to the GDPR; Ada Health GmbH in Berlin as the data controller; storage of personal data within the EU; a statement that health data and other sensitive data always remain within the EU; listing of data processors and Data Processing Agreements pursuant to Art. 28 GDPR; published list of service providers; ISO 27001 and ISO 13485 certifications on the website; security page with a statement regarding EU servers and “security by design.”


**Negative**


Negative or limiting aspects include: According to the privacy policy, limited processing by subprocessors outside the EEA may take place; the list of service providers includes several U.S. providers; an explicit customer DPA is not listed on the website as a freely accessible document; an explicit EU data residency commitment for all data flows across all product variants is not fully articulated; On-premises, self-hosting, and private cloud options are not listed on the website; a clear contractual “no training” path for all inputs and outputs is not specified on the website.


**Server Location**


The website lists the EU as the storage location. The privacy policy states that personal data is stored in the European Union on cloud servers operated by AWS EMEA in Luxembourg and Google Commerce Limited in Ireland. The “How is my data stored by Ada?” help page specifically mentions a Google Cloud location in the EU, “Europe-West1” in Belgium, as well as MongoDB Cloud Services in that data center. Additionally, the privacy policy states that health data and other sensitive data always remain within the EU. However, limited data may be processed by subprocessors outside the EEA.

## Hosting und Daten
- **On-Prem / lokales Hosting:** unknown
- **Private Cloud / Rechenzentrum:** teilweise / indirekt
- **EU SaaS / Managed:** abgedeckt
- **Hybrid:** unknown
- **AVV / DPA:** teilweise / indirekt
- **Kein Training auf Kundendaten:** teilweise / indirekt
- **Open-Source / Transparenz-Pfad:** unknown

## Standort
**Land:** Germany

**Taxonomie:** Germany

Ada Health GmbH, Neue Grünstraße 17, 10179 Berlin, Germany.

## Vorteile
- Strong medical specialization instead of a generic health chatbot.
- Free consumer access.
- Enterprise features for care navigation, clinical handover, and insights.
- Regulatory and quality signals: EU-MDR Class IIa, ISO 27001, ISO 13485.
- Public privacy documentation with DPO, processor list, and EU storage of sensitive data.
- Broad integration capability via web, app, portal, and FHIR/EHR/CRM.

## Nachteile
- Not a substitute for medical diagnosis; Ada explicitly states this itself.
- No public B2B pricing or self-serve enterprise plans.
- For generic SMEs outside healthcare, there is usually no suitable standard use case.
- Parts of the infrastructure/processors are located outside the EEA; therefore, data protection review remains relevant despite a good foundation.
- According to the privacy policy, unencrypted email communication is not end-to-end encrypted.

## Quellen
- Offizielle Website: https://ada.com/

## Letzter Datenstand
2026-05-01

## Originalseite
https://kifox.ai/en/ki-tools/ada-health-en/
