Security · Compliance

Security & compliance

Health data is our first responsibility. Here is where it lives, how it is protected, and the frameworks we comply with.

01

Data residency

You choose the jurisdiction: Switzerland, France or another European Union country. Patient data stays in the chosen territory and under your jurisdiction — it is never transferred outside that perimeter without your agreement. Our datacenters comply with the Swiss nLPD and the GDPR.

02

Compliance and hosting

We rely on recognised frameworks, and claim nothing beyond what can be verified:

nLPD RGPD ISO 27001 · host
  • ISO/IEC 27001 — our hosting provider is certified for information security management.
  • Security reviews — code and infrastructure are reviewed regularly; critical findings are fixed before any production release.
  • nLPD & GDPR — compliance with the Swiss and European data-protection regimes.

A summary of our security measures is available under a non-disclosure agreement (NDA), on request at contact@globalaccess.ch.

03

Encryption & processing

Data is encrypted in transit (TLS) and at rest. Exchanges between the on-premise hospital components and the cloud are mutually authenticated (mTLS). Direct patient identifiers are segregated from the rest of the record.

For voice dictation and the copilot, data is anonymized before any processing by an external model. Prescription OCR is handled by a provider under a data-processing agreement, with no retention and no training on your documents.

04

Audit trail

Every sensitive action — reading or modifying a report — is logged: who, what, when, from which address. Audit logs are retained in line with legal obligations and remain available for inspection.

05

Sovereignty & subprocessors

Your data belongs to you. It is neither sold nor shared with third parties for commercial purposes. A data processing agreement (DPA) governs each processing activity; the list of subprocessors is provided on request.

06

Retention & deletion

Data is retained only as long as strictly necessary and deleted once the applicable legal periods expire. No indefinite retention of personal health data.

07

Responsible disclosure

Found a vulnerability? Write to contact@globalaccess.ch. We handle security reports as a priority and commit to responding quickly.

Last updated: June 2026 · Global Access SA