Skip to content

Security & Compliance

How the RestartiX platform protects patient data, meets regulatory requirements, and maintains trust.


The platform handles sensitive health information for every patient and clinic on the system. Security and compliance are not add-ons — they are built into the architecture from day one.

At a Glance

AreaWhat We DoLearn More
Data IsolationEach clinic's data is separated at the database level — no application bug can cross boundariesHow clinic data stays separate
EncryptionData encrypted in transit and at rest, with application-level encryption for the most sensitive fieldsWhat's encrypted and how
Audit TrailEvery data mutation is logged — who did what, when, from where — immutable and retained for 6 yearsWhat's logged and for how long
GDPRFull compliance with European data protection law — consent management, data portability, right to erasureEU data protection
HIPAAReady for US healthcare market — PHI protection, audit controls, breach notificationUS healthcare compliance
Patient RightsPatients control their data — access, correct, delete, export, and withdraw consent at any timeWhat patients can do

Medical Device Regulation

The platform's clinical features — exercise prescription, treatment plans, and camera-based clinical measurement tools (virtual goniometer, posture analysis) — qualify it as a Software as a Medical Device (SaMD) under EU MDR.

The measurement tools are expected to classify as Class IIa (moderate risk), because they provide clinical data that specialists use to make treatment decisions — replacing physical instruments like goniometers. This is separate from data protection (GDPR/HIPAA) but equally important for operating legally in the EU healthcare market.

Regulatory areaWhat it coversLearn more
Data protection (GDPR, HIPAA)How patient data is collected, stored, shared, and protectedThis section
Medical device (EU MDR, IEC 62304)How clinical software is developed, tested, validated, and maintainedMedical Device Classification

Both are required. GDPR compliance does not satisfy medical device requirements, and vice versa.


Our Roles

RoleWhoResponsibility
Data ProcessorRestartiX (the platform)Provides infrastructure, processes data on behalf of clinics. Does not decide what data is collected.
Data ControllerEach clinicDecides which services to offer, what forms to collect, how patient data is used.
Data SubjectThe patientOwns their data. Controls which clinics can access their profile.

RestartiX signs a Data Processing Agreement (DPA) with every clinic. Each clinic is independently responsible for its own privacy policy and patient consent.


Compliance Status

The full compliance checklist covers every legal document and requirement for launch — organized by party (platform, clinic, patient) and phase (day-one EU launch vs. future US expansion).

View the full Compliance Checklist →

See Medical Device Classification for the regulatory assessment of the platform's clinical features.


For developers

Technical implementation details — RLS policies, encryption algorithms, audit middleware, RBAC configuration — are available in the Technical Reference section of the Development Documentation.