Compliance

Regulatory alignment you can trust

Our platform is designed from the ground up to support compliance with healthcare and data protection regulations across jurisdictions.

GDPR Compliant
European data protection
End-to-End Encryption
Data encrypted at rest & transit
EU Data Residency
Data stays in Europe
Privacy by Design
Built for confidentiality
GDPR

General Data Protection Regulation

As a European company, GDPR compliance is fundamental to how we operate. We don't just meet requirements—we embrace the principles that protect user rights.

Lawful Basis for Processing

We process personal data only with valid legal bases, primarily consent and legitimate interest for service delivery.

Data Subject Rights

Full support for access, rectification, erasure, portability, and objection rights. Users can exercise these rights at any time.

Data Protection Impact Assessments

Regular DPIAs conducted for processing activities involving health data to ensure risks are identified and mitigated.

Data Processing Agreements

Comprehensive DPAs with all sub-processors, ensuring the entire data chain maintains GDPR standards.

Healthcare

Healthcare data standards

Our platform architecture aligns with healthcare data handling best practices and industry standards.

Data Classification

Health information is classified and handled according to sensitivity levels, with appropriate controls for each category.

Access Controls

Role-based access controls ensure that only authorized personnel can access specific data types, with full audit logging.

Audit Trails

Comprehensive logging of all data access and modifications, supporting accountability and incident investigation.

AI Governance

Responsible AI principles

As AI regulation evolves, we proactively align with emerging standards for responsible AI deployment in healthcare contexts.

  • Transparency in AI decision-making processes
  • Regular bias testing and mitigation
  • Human oversight for critical determinations
  • Clear limitations disclosure to users
  • Continuous monitoring for AI performance
  • Alignment with EU AI Act requirements

Important Disclaimer

DrGuido is an informational support tool and is not classified as a medical device. It does not diagnose conditions, prescribe treatments, or provide medical advice. Users should always consult qualified healthcare professionals for medical decisions.

Our AI provides contextual health information and helps users understand medical documents, but the responsibility for medical decisions remains with healthcare professionals and informed patients.

Need compliance documentation?

Our team can provide detailed compliance documentation for enterprise evaluation and due diligence processes.