Clinical security & AI
Assistive AI. Not decisive.
Technology organizes the signal. The clinical team interprets, decides and acts.
🔒GDPR
📜LOPDGDD
📋DPA
👁️Access audit trail
🔐Encryption at rest & transit
🧩Field-level encryption of clinical data
What AI does and what it doesn't.
AI does
- Summarises what the patient already logged, to prepare each session
- Drafts descriptive summaries the professional reviews and approves
- Retrieves and quotes the record verbatim, with date and source
- Helps moderate the community, always with human review
AI does not
- Does not issue diagnoses or clinical assessments
- Does not score, classify or predict
- Does not make decisions or act without human supervision
- Does not receive identities: information is anonymised before being sent
Privacy by design
Security from the code.
Role-based access
Each profile sees only what the protocol allows. No exceptions.
Data minimization
Only what's needed for clinical follow-up is collected.
Full audit trail
Immutable record of who accessed what and when.
Regulatory compliance.
🔒 GDPR📜 LOPDGDD📋 DPA👁️ Access audit trail🔐 Encryption at rest & transit🧩 Field-level encryption of clinical data
Design commitments.
These principles aren't marketing. They're reflected in the product architecture and the DPA contract.
AI never issues diagnoses or treatment suggestions
Sensitive modules (location, wearables, AI, community) are only activated with the patient's express consent
Accesses are recorded in the audit log
Deletion rights are honoured under the GDPR, respecting legal clinical retention periods