Skip to main content
CareBond

Compliance

Compliance by architecture, not by addendum.

GDPR and nLPD by design, Swiss hosting, immutable audit log. Compliance isn't a layer we added — it's built into the platform from line one.

GDPR & nLPD by design

Native audit log of accesses and modifications, built for the requirements of the EU GDPR and the Swiss nLPD from the first line of code.

Swiss hosting

Infrastructure hosted at Infomaniak (Geneva), in a country holding a European Commission adequacy decision. Patient data never leaves that infrastructure — no exception, no hidden clause.

Modern encryption

Modern TLS in transit, encryption of sensitive fields (PHI), HMAC-signed visit reports.

Immutable audit log

An immutable trace of every access and change, exportable for your internal and external audits. Granular RBAC and multi-institution support.

Regulatory framework

One framework, multiple jurisdictions.

CareBond was born under one of the world's strictest data protection laws and extends that same architecture to the European frameworks. Here are the main frameworks we address.

  • GDPR (EU)

    General Data Protection Regulation. Data minimization, traceability, rights of access and erasure: CareBond's architecture is designed for GDPR requirements. Switzerland also holds a European Commission adequacy decision for data transfers.

  • nLPD (Switzerland)

    Federal Act on Data Protection. Native audit log, rights of access and rectification, complaint route to the FDPIC documented in our privacy policy.

  • KVG / LAMal (Switzerland)

    Cryptographically signed (HMAC) visit reports, with a traceable record to support billing to Swiss health insurers for home care.

  • International transfers

    The only transfer outside Switzerland is the site hosting (Vercel, fra1 Frankfurt), governed by Standard Contractual Clauses and documented. Contact form emails stay in Switzerland, on our mail server at Infomaniak.

Certifications

Targeted certifications

Beyond the GDPR and nLPD requirements and the data sovereignty already covered by our architecture, CareBond aims to obtain the international certifications expected by hospital procurement teams.

  • Medium-term target

    ISO/IEC 27001

    Information security management system. Certification set as a medium-term target.

  • Target (reference)

    HDS — French Health Data Host

    French reference for health data hosting, considered as a comparative target. Our main argument is hosting in Switzerland.

Technical documentation

Your legal and IT teams want the details?

We keep complete technical documentation available: architecture, data flows, audit log, retention policies, processor contract templates. On request, with no form to fill out.