Ir para o conteudo principal

GDPR Compliance

Overview

vitalera fully complies with the General Data Protection Regulation (GDPR), ensuring the protection and privacy of personal health data for all users within the European Union. As a CE-marked MDR medical device software platform for remote patient monitoring, GDPR compliance is integral to how vitalera handles patient vital signs, clinical observations, and healthcare communications.

Key Principles

PrincipleImplementation
LawfulnessData processing based on consent and legitimate interest
Purpose LimitationData collected only for specified healthcare purposes
Data MinimizationOnly necessary data is collected and processed
AccuracyTools for patients to review and update their data
Storage LimitationData retention policies aligned with regulatory requirements
SecurityEncryption, access controls, and security monitoring

Data Subject Rights

vitalera supports all GDPR data subject rights:

  • Right of Access: Patients can view all their personal data
  • Right to Rectification: Patients can update incorrect data
  • Right to Erasure: Account deletion functionality available
  • Right to Data Portability: Data export in standard formats
  • Right to Object: Patients can withdraw consent at any time

Data Residency

All patient data is stored in the EU (Ireland, eu-west-1) on AWS infrastructure with AES-256 encryption at rest and TLS 1.2+ in transit. No health data leaves the European Economic Area.

Data Processing

  • Data Controller: The healthcare organization using vitalera
  • Data Processor: FOLLOWHEALTH S.L. (vitalera platform operator)
  • Data Processing Agreement: Available for all clients