Security · Compliance

Security & compliance

Health data is our first responsibility. Here is where it lives, how it is protected, and the frameworks we comply with.

01

Data residency

You choose the jurisdiction: Switzerland, France or another European Union country. Patient data stays in the chosen territory and under your jurisdiction — it is never transferred outside that perimeter without your agreement. Our datacenters comply with the Swiss nLPD and the GDPR.

02

Certifications

Our infrastructure and processes are audited against the most demanding standards in the industry:

HDS ISO 27001 SOC 2 Type II nLPD RGPD
  • HDS — certified health-data hosting.
  • ISO/IEC 27001 — information security management.
  • SOC 2 Type II — annual audit of security controls.
  • nLPD & GDPR — compliance with the Swiss and European data-protection regimes.

Audit reports are available under a non-disclosure agreement (NDA), on request at contact@globalaccess.ch.

03

Encryption & processing

Data is encrypted in transit (TLS) and at rest. Exchanges between the on-premise hospital components and the cloud are mutually authenticated (mTLS). Direct patient identifiers are segregated from the rest of the record.

For AI features (voice dictation, prescription OCR), data is anonymized before any processing by an external model.

04

Audit trail

Every sensitive action — reading or modifying a report — is logged: who, what, when, from which address. Audit logs are retained in line with legal obligations and remain available for inspection.

05

Sovereignty & subprocessors

Your data belongs to you. It is neither sold nor shared with third parties for commercial purposes. A data processing agreement (DPA) governs each processing activity; the list of subprocessors is provided on request.

06

Retention & deletion

Data is retained only as long as strictly necessary and deleted once the applicable legal periods expire. No indefinite retention of personal health data.

07

Responsible disclosure

Found a vulnerability? Write to contact@globalaccess.ch. We handle security reports as a priority and commit to responding quickly.

Last updated: June 2026 · Global Access SA