Security and clinical data

Protection controls, contractual scope and responsibilities for your practice.

Pseudonymous references and access

Use pseudonymous references and keep the identity mapping separately. These remain personal data; avoid names and identifiers in notes and support. We apply practice access controls and sign a DPA; support access is limited and logged under the contract.

Protection and limits

We use TLS, access controls and encryption for clinical fields and backups. These controls reduce risk; they cannot eliminate every incident. See privacy and the DPA for scope, providers and limits.

Infrastructure and providers

The contract provides clinical storage and backups in the EU. CDN, observability, authentication and support may involve other access or transfers; review the provider register and safeguards. A whole brand is not presumed covered by the DPF.

Incidents and assistance

We inform the controller of personal data breaches without undue delay after awareness and provide available information. The controller's 72-hour authority notification deadline applies where required. We normally answer audit questionnaires within ten business days; we claim no unverified certifications.

Exit and retention

You can export customer data in the available formats. After termination the contract provides exit access until D+30, production deletion by D+60 and backup expiry by D+97, subject to legal exceptions and valid instructions. Switching providers may adjust these periods.

Professional use and requirements

The professional determines indication and supervision. Intended purpose, version and territory determine regulatory requirements; review the module factsheet and contract before use. We claim no medical certification or blanket exemption.

Email support Monday to Friday, 09:00–18:00 (Europe/Madrid), excluding holidays at the provider's domicile. It is not an emergency service or continuous monitoring.

Security and clinical data protection · VRET