A plan for the person who has an hour to judge whether a clinic using Heltio has its patients' data under control: a data protection officer, an auditor, external counsel, or an owner doing a review ahead of an inspection.
Heltio is the processor within the meaning of Article 28 GDPR, and the clinic is the controller. This audit checks both: what the clinic does, and what Heltio gives it to do it with.
How to do it
Three of the five steps of this audit happen on one screen. One is the settings' own navigation — from here you enter GDPR & Privacy, and here you come back for the Audit Log in step 4. Two is the Compliance Overview card with its three numbers, where step 1 begins.
Records of processing activities (10 minutes)
Settings → Compliance → GDPR & Privacy. At the top, the Compliance Overview card with three numbers: Pending Requests, Overdue Requests and Retention Period. An overdue request on that tile is the only place where the clinic will see a missed statutory deadline before the patient does.
The Records of Processing Activities section has a Download RoPA (JSON) button. The file is built from the clinic's actual configuration, not from a template, and the download is recorded in the audit log — but it is not a finished Article 30 register. It contains the clinic name, the data-protection contact address, the retention period, the consent categories with their legal basis, record counts and the composition of the team. It does not contain the recipients of the data, transfers outside the EU, a description of the security measures, or the DPO's details. Treat it as input material for a register kept outside Heltio.
Retention and the point of contact (10 minutes)
The retention section holds a single field: the retention period in years. A new clinic starts at 20 years, and the control accepts values from 6 to 99.
Below that, Data Controller Contact — the GDPR contact email field, the address that goes into the privacy policy and that the patient sees when filing a request. An empty field means there is no route for a complaint.
Data subject requests (20 minutes)
The Data subject requests table covers all six rights: Access (Art. 15), Rectification (Art. 16), Erasure (Art. 17), Restriction (Art. 18), Portability (Art. 20) and Objection (Art. 21). Every row carries the date received and the Deadline; a missed one is marked Overdue.
The patient files a request themselves, in the privacy section of the patient portal. A request that came by post, by e-mail or over the desk is entered with the Register a request button — the dialog asks for the channel, the Date received, and how the requester's identity was verified (Art. 12(6)). The deadline runs from the date it arrived, not from the date it was entered; the form says so outright.
Check three things, because that is where the procedure most often breaks:
- Extension by two months requires a reason and may be applied once per request (Art. 12(3)). The patient receives an e-mail with the new deadline.
- Refusal also requires a reason, and the message to the patient contains the notice about the right to complain and to go to court (Art. 12(4)).
- Complete and generate export first creates the redacted copy of the data and only then closes the request. If the copy fails, the request stays open — deliberately.
Completing an erasure request deletes the patient record together with their identity at the authentication provider and their attachments; the request row disappears with the patient, and the audit log is the only lasting trace.
The audit log (10 minutes)
Settings → Compliance → Audit Log. The filters: date range, User, Action type, Entity type and record ID. You pull one patient's history out with the last two filters. Export returns exactly what the filters show, in JSON or CSV.
Entries cannot be changed or deleted from inside the app — not even by the clinic owner. Reading the log leaves no entry in it; every export does.
Entries older than the configured retention period are deleted automatically by Heltio, apart from billing events and events arising from the GDPR, which stay regardless of that setting.
The patient sees their own Activity history in the portal — Article 15(1)(c) discharged without staff involvement.
Sub-processors and encryption (10 minutes)
The current sub-processor list is public, on the Sub-processors page: the database and files in Frankfurt, encryption keys in AWS KMS in Frankfurt, SMS through LINK Mobility in Poland, payments through Przelewy24 in Poland, authentication through Clerk. Heltio gives clinics thirty days' notice of a change to that list, and the clinic has a right to object. Language-model providers and Google Calendar sync are on the same page, in the Paused / disabled part.
The PESEL number is encrypted separately in the database, with a key held outside it; searching by number works on a digest, not on the content. The rest of the data is encrypted at the disk and connection level.
What this audit will not confirm
Four things Heltio does not have, which an earlier version of this plan told you to look for:
- A field for the data protection officer's details. The clinic settings have nowhere to record the DPO's name or contact. The details Article 30 requires have to be kept outside Heltio.
- A "support session" mode and a Heltio service account. The previous version described time-limited access by a Heltio employee, recorded in the audit log with a special marker. No such mechanism exists.
- A checksum on audit-log entries. The entries are immutable because the app has nothing with which to change them — not because of a cryptographic signature.
- A public trust centre and certifications. There is no page with external audits; Heltio holds neither SOC 2 nor ISO 27001 today.
When something does not work
You need owner or admin permissions to access GDPR settings. Contact your clinic administrator.
What this means: The account holds the Practitioner or Assistant role in this clinic.
There are overdue deletion requests requiring immediate attention
What this means: At least one request has passed the one-month deadline under Art. 12(3).
This request is already past its statutory deadline. Treat it as urgent.
What this means: The date received entered when the request was registered is more than a month old.
This patient has no e-mail address on file, so the acknowledgement cannot be sent automatically.
What this means: The request concerns a person with no e-mail address on the patient record.
Related
- Data subject rights — the full description of the six rights and the routes to fulfilling them.
- Retention policy — how long each kind of data lives.
- Audit log — filters, export and the range of events recorded.
- Incident reporting procedure — what to do within 72 hours of detecting a breach.