GDPR & nLPD by design
Native audit log of accesses and modifications, built for the requirements of the EU GDPR and the Swiss nLPD from the first line of code.
Compliance
GDPR and nLPD by design, Swiss hosting, immutable audit log. Compliance isn't a layer we added — it's built into the platform from line one.
Native audit log of accesses and modifications, built for the requirements of the EU GDPR and the Swiss nLPD from the first line of code.
Infrastructure hosted at Infomaniak (Geneva), in a country holding a European Commission adequacy decision. Patient data never leaves that infrastructure — no exception, no hidden clause.
Modern TLS in transit, encryption of sensitive fields (PHI), HMAC-signed visit reports.
An immutable trace of every access and change, exportable for your internal and external audits. Granular RBAC and multi-institution support.
Regulatory framework
CareBond was born under one of the world's strictest data protection laws and extends that same architecture to the European frameworks. Here are the main frameworks we address.
General Data Protection Regulation. Data minimization, traceability, rights of access and erasure: CareBond's architecture is designed for GDPR requirements. Switzerland also holds a European Commission adequacy decision for data transfers.
Federal Act on Data Protection. Native audit log, rights of access and rectification, complaint route to the FDPIC documented in our privacy policy.
Cryptographically signed (HMAC) visit reports, with a traceable record to support billing to Swiss health insurers for home care.
The only transfer outside Switzerland is the site hosting (Vercel, fra1 Frankfurt), governed by Standard Contractual Clauses and documented. Contact form emails stay in Switzerland, on our mail server at Infomaniak.
Certifications
Beyond the GDPR and nLPD requirements and the data sovereignty already covered by our architecture, CareBond aims to obtain the international certifications expected by hospital procurement teams.
Information security management system. Certification set as a medium-term target.
French reference for health data hosting, considered as a comparative target. Our main argument is hosting in Switzerland.
Technical documentation
We keep complete technical documentation available: architecture, data flows, audit log, retention policies, processor contract templates. On request, with no form to fill out.