Our Approach to Data Protection

Last updated / effective: August 9, 2026

AXOTIA is in a pre-launch stage. This page describes our approach and the gates required before production; it is not a compliance certificate or a claim that a patient-data backend exists today.

1. Current state

  • The public website introduces the planned product and lets prospective customers contact us.
  • There are no production customer accounts, online payments, patient portal, or AXOTIA backend processing health records, images, or patient messages.
  • The public website uses HTTPS, Vercel hosting, cookie-free analytics, and performance measurement.

2. Gates before real data is processed

  • Verified architecture: actual hosting regions, encryption, access controls, customer isolation, logging, backups, and recovery must be implemented and tested.
  • Contracts and legal roles: the service agreement, actual DPA, subprocessor list, and international transfer mechanisms must match the real system and receive legal review.
  • Operational controls: retention and deletion, incident response, authorization, human oversight, and the prohibition on autonomous clinical decisions must be documented and verifiable.
  • Market-specific review: before serving EU or U.S. healthcare customers, we will assess applicable GDPR, EHDS, HIPAA, and other requirements, including any contracts actually required for that use case.

3. Administrative, not medical

AXOTIA's planned role is communication, administrative intake, and scheduling support. It is not intended to diagnose, recommend treatment, provide emergency medical care, or replace the judgment of a licensed healthcare professional.

4. Publishing verified commitments

We will publish specific claims about providers, regions, encryption methods, data isolation, exports, deletion, and compliance only after they are implemented, contracted, and verified.

For the website's current data handling, read our Website Privacy Notice.