Data Security & Privacy

Frequently Asked Questions

Everything practitioners need to know about how MyDosha handles patient data, GDPR compliance, and your rights as a data controller.

Access & Visibility
Who can see my patient data?

Only you. Clinical records, intake answers, exam notes, and care plans are visible solely to the logged in practitioner for that account. MyDosha staff have no access to your patient records. Data is encrypted at rest and in transit.

Can MyDosha employees read my patients' notes?

No. The application is built so that clinical content is only accessible through authenticated practitioner sessions. There is no admin back door into patient records. Support queries are handled without access to clinical data.

Can another clinic that signs up see my patients?

No. Every clinic's records are partitioned by a clinic identifier, and every single data request — including anything the AI assistants read — is scoped to the signed-in clinic on the server. Signing up gives a new account access only to its own records (a couple of demo patients on a trial); it provides no path to anyone else's data. This isolation is enforced in the database layer and covered by an automated regression test plus a static check on every change.

Do patients have access to their own records?

Patients can access a read only summary of their prakriti profile and care plan through the patient portal, protected by a magic link sent to their email address. They cannot view practitioner exam notes or the full clinical record.

Data Storage & Location
Where is patient data stored?

All patient records are stored on Supabase, using data centres in Frankfurt, Germany (AWS eu-central-1). Storage is in the European Union.

Supabase is certified under ISO 27001 and SOC 2 Type II. Supabase Inc. is US-incorporated, so its Data Processing Agreement incorporates the EU Standard Contractual Clauses to cover any support access from outside the EEA.

Storage is not the whole picture: generating the AI dossier sends the patient’s intake answers to Anthropic’s Claude API in the US, and the application itself runs on Vercel’s edge network (EU + US). Both are covered by the same Standard Contractual Clauses. See the full sub-processor list.

Is data shared with companies in the US, China, or other third countries?

Patient data is not shared with any third parties for commercial, research, or marketing purposes. The sub-processors involved are Supabase (database & file storage, EU region), Vercel (application hosting), Anthropic (AI processing for the dossier and in-portal assistants), and Resend (transactional email). Each is bound by a Data Processing Agreement incorporating the EU Standard Contractual Clauses. Anthropic’s API terms prohibit training on customer data.

MyDosha does not sell, license, or transfer patient data to universities, research institutions, pharmaceutical companies, or any other external party.

AI Processing
Is patient data used to train AI models?

No. AI processing (used to generate the intake dossier) happens in session only. Patient data is processed to generate the response and is not retained, stored, or used for training. MyDosha operates under the Anthropic API terms, which prohibit training on customer data.

What does the AI actually do with patient information?

The AI reorganises the patient's self reported intake answers into a structured prakriti and vikriti summary for the practitioner. It does not diagnose, recommend treatments, or screen for drug interactions on a per patient basis. All output is framed as "the patient reported" rather than as a clinical finding. The practitioner remains the sole clinical decision maker.

This positions MyDosha as a non device intake and reference tool under MDCG 2019-11 Rev.1. See our intended use statement for the full scope.

Could someone use the AI assistant to extract another clinic's patient data?

No. The assistants only ever receive the records belonging to the signed-in clinic — data is filtered to your clinic before it reaches the model — and they have no ability to query the database or fetch anything on their own. Because the clinic boundary is enforced in our database layer beneath the AI rather than by the AI's instructions, manipulating the assistant's wording cannot make it cross into another clinic's records. We also screen intake text and AI output to keep the assistant within its intended, non-diagnostic scope.

GDPR & Legal
Is MyDosha GDPR compliant?

Yes. MyDosha operates as a data processor under GDPR Article 28. The practitioner is the data controller and remains responsible for the lawful basis for processing patient data (typically legitimate interest or explicit consent for health data under Article 9).

A signed Data Processing Agreement (DPA) is provided with every paid plan. The supervisory authority is the Italian Data Protection Authority (Garante per la protezione dei dati personali).

Can I delete patient records?

Yes, at any time, directly from the practitioner portal. Records are permanently deleted from the database within 30 days. This supports your ability to honour patient right to erasure requests under GDPR Article 17.

What happens to my data if MyDosha shuts down?

Practitioners can export all patient data as a structured file at any time from the portal settings. In the event of a service discontinuation, all account holders would be given advance notice and a final export window before data is deleted.

Is MyDosha a medical device?

No. MyDosha is a practitioner administration and intake tool, not a medical device under EU Regulation 2017/745. It does not diagnose, treat, or make clinical recommendations. See our intended use statement for the full regulatory scope.

Data Processing Agreement

A signed DPA is included with every paid MyDosha plan. If you need a copy for your records or for a compliance audit, contact hello@mydosha.org and we will send one within one business day. Further detail on sub-processors and data flows is available in our privacy policy.

Still have questions?

We are happy to speak with you directly about data security, compliance, or how the platform works in practice.

Get in touch