Security and data

Security that starts with where your data lives

Database, file storage and cache are hosted in EU regions, and health data is treated as special category data throughout. Any remote access from outside the UK/EEA is limited, safeguarded and only for support or security.

Why data location is your problem, not just ours

If your practice software stores records outside the UK or EEA, every movement of that data is a restricted international transfer of special category health data, and you are the controller responsible for it. Not your vendor. You.

Patient and clinical data is hosted and stored within the European Economic Area, subject to limited remote access from outside the UK/EEA where necessary for support, security or incident response and protected by appropriate safeguards. That keeps international transfers of your patients' data to a narrow, documented minimum, listed on our sub-processors page. It is a deliberate architectural decision, made before the first line of the schema.

How patient data is protected

What is actually built and running today. Nothing on this page is a roadmap item.

Where your data lives

  • The database and cache run in the EU (Frankfurt).
  • Uploaded files are stored in Cloudflare R2's EU region and only ever served through short-lived signed links.
  • Health data is treated as special category data throughout.

Access control

  • Owner, manager, practitioner and receptionist roles, with permissions checked on sensitive actions such as billing, team changes, exports and erasure.
  • TOTP two-factor authentication with single-use backup codes.
  • Login rate limiting per email address and per IP address.
  • Passwords hashed with bcrypt; two-factor secrets encrypted at rest with AES-256-GCM.

Clinical confidentiality

  • Every note carries one of three visibility tiers: patient-visible, internal or confidential.
  • The patient portal's query only ever returns patient-visible notes, so an internal or confidential note cannot surface there.
  • Each saved edit keeps the previous version, and a signed note locks so it cannot be silently rewritten.

Audit

  • Significant actions are written to a dedicated audit log, kept apart from the clinical records it describes.
  • Every patient export is logged with who ran it, when, from where and how many records, after a confirmation step.
  • If an Atlacare administrator ever opens your account to help, the start and end of that session go into your audit log.

Analytics discipline

  • Analytics are never loaded in the clinic app or the admin panel. Those URLs contain patient identifiers, so sending them to an analytics provider would itself be an Article 9 problem.
  • On public pages, analytics stay off until the visitor consents. This is enforced in code, not set as a preference.

Sub-processors

  • Published publicly, with what each provider does and where it operates.
  • A new provider goes on the list before a feature that uses it ships, not after.

No AI provider

  • No AI feature exists and nothing is sent to any AI API. That is a deliberate position, not a gap.
  • If it ever changes, the provider goes on the public sub-processor list first.

Your data is yours

  • Export your patient list as CSV whenever you want, on every plan.
  • Produce one patient's full record (details, appointments, notes and invoices) as a PDF for a subject access request.
  • Retention is country-aware across 16 countries. Erasure is blocked while records are inside the retention period, then anonymises personal details and is audit-logged.

Security and data: common questions

Where exactly is patient data stored?

In EU regions: the database and cache in Frankfurt, and file storage in Cloudflare's EU region. Patient and clinical data is hosted and stored in the EEA, with only limited, safeguarded remote access from outside the UK/EEA where needed for support or security. The one provider outside is Loops (US), which sends product email to clinic account owners and never receives patient data.

Is Atlacare GDPR compliant?

Compliance is a property of your practice, not only of your software, because you are the controller. What we provide is the infrastructure for it: EU residency, special category handling, consent tracking, audit logging, country-aware retention, and per-patient subject access exports.

Do you use patient data to train AI?

No. There is no AI feature, no AI provider on our sub-processor list, and nothing is sent to any AI API.

Can your support team see our patient records?

Account access by Atlacare is restricted to platform administrators, and every time an administrator opens your account, the start and end of that session are written to your practice's audit log.

What happens to our data if we stop paying?

You export it. Patient-list CSV export and per-patient record exports are available on every plan, including Free, so downgrading never locks you out of your records.

Your patients' data, kept in the EEA

Try Atlacare free, with no card and no time limit.

Try Atlacare free

No credit card · 20 patients free forever

Want the detail? Read the sub-processor list