Security and privacy
You handle health data, and we treat it with that level of care. This is what we do to protect your clinic's and your patients' information.
1Health data under the GDPR
We treat your patients' data as special-category data under the General Data Protection Regulation. We only collect the information needed to manage appointments, records and exercise plans, and we never share it with third parties for advertising purposes.
2Encryption in transit
All communication between your browser, your patients and our servers travels encrypted via HTTPS/TLS. Certificates renew automatically.
3Passwordless sign-in
Neither you nor your patients manage passwords: sign-in uses single-use magic links sent by email. There are no credentials to steal or reuse.
4Own, isolated infrastructure
The platform runs on dedicated servers managed by us, with the application and database isolated in containers. No third-party service dependency for the system core.
5Daily backups
The database is backed up automatically every day (pg_dump) with a 14-day retention. The restore process is verified: we periodically test that backups can actually be recovered, not just created.
6Your data is yours
You can export your clinic's information or request its deletion at any time. Patients can exercise their rights of access, rectification, objection and erasure by contacting the clinic.
Questions about security? Write to us and we will answer with technical detail.