Compliance and GDPR
Formal documentation for DPOs, auditors and data protection inspectors. All GDPR materials for Heltio in one place.
GDPR compliance overview
Heltio's role as a data processor, legal basis for processing, and records of processing activities.
DPA and sub-processors
Data Processing Agreement, list of sub-processors (Clerk, Supabase, Resend, P24, P1, Google) and links to their DPAs.
Data retention policy
Retention schedule by data type: medical records (20 years), audit log (5 years), billing data and more.
How the audit log works
What is logged and when, how to export logs, record format and retention requirements.
Data subject rights (DSR)
Handling DSR requests: access, rectification, erasure, restriction, objection and data portability.
Encryption and data residency
Field-level encryption (PESEL), at-rest and in-transit encryption. Data residency exclusively in the EU.
P1 + EDM: compliance status
Compliance with P1 (RPWDL, ZM, EDM), certificate statuses, IPL and audit requirements.
Roles and permissions (ClinicRole)
Formal description of the ClinicRole model: Admin, Receptionist, Practitioner, ClinicViewer and the permissions matrix.
Incident reporting procedure
How to report a personal data breach — to Heltio and by Heltio to the supervisory authority.
Consent management (PKE)
PKE consents per communication channel, marketing opt-in and AI feature opt-in.