Security and data protection

Awedeed holds some of the most sensitive data a business can hold, so it is built the way health data demands. Here is exactly what that means — no more, no less.

Hosted in the EU

Everything is stored in Frankfurt, Germany, and stays inside the EU. Your patients’ data never leaves European soil.

Encrypted everywhere

Data is locked with strong encryption while it is stored and while it travels. Card details never reach us at all — they go straight to our payment provider.

Permissions, per action

Access is granted action by action — viewing patients, moving appointments, changing settings — so each person sees and does exactly what their role requires.

Every access on the record

Opening a patient record is logged, not just editing it. Views, changes and actions build a timeline on every record, kept for a full year.

Continuous backups

Backups run continuously, not once a night. We can wind your clinic’s data back to any moment in the last 35 days — just yours, without touching anyone else’s.

Credentials kept apart

Passwords live in a separate vault that holds no patient data, so one door never opens the other. Your patients have no password at all — they sign in with a code sent to their email.

How Awedeed helps with GDPR

No software can make a clinic GDPR-compliant on its own — part of the work is how your clinic operates. What Awedeed does is carry the technical side, so the questions an auditor asks have answers.

Your clinic stays in control

Under GDPR your clinic is the data controller. Awedeed processes patient data only on your behalf and on your instructions — you decide what is collected and who may see it.

Evidence, when you're asked for it

Accountability means being able to show who accessed what. The audit trail answers that for every record — views, changes, and sign-ins by both staff and patients — covering the last 365 days.

Consent, versioned

Your team accepts the current Terms and Privacy Policy inside the app, and every acceptance is recorded against the exact version that was shown.

The right to be forgotten

Individual records can be archived, and when a clinic leaves Awedeed its data is deleted within 30 days, except where the law requires us to keep it longer.

Nothing lingers by accident

Team chat messages delete themselves after 24 hours and activity logs expire after a year. Data is kept for as long as it serves a purpose, and no longer.

Fewer ways in

The sign-in form gives the same answer for a wrong email and a wrong password, so it cannot be used to discover who works at your clinic. Sessions expire after 60 minutes and renew for at most 30 days.

Does your DPO have questions?

Put them in front of us. We would rather answer a hard question before you sign up than after.

Write to contact@filipmanole.com