Security and compliance by design.

How we protect data, how the platform can be deployed and how it supports regulatory traceability.

Data protection

The platform is designed in line with the GDPR (Regulation (EU) 2016/679) and the Spanish data protection law (LOPDGDD).

  • Access control by role: each person sees only what their work requires
  • Traceability of actions: relevant operations are recorded
  • Data minimisation: we process only the data each process needs
  • Hospital data is processed under a data processing agreement (article 28 GDPR)

Deployment options

The platform can be deployed in the cloud or on-premises, in the hospital's own infrastructure, depending on each organisation's security policy and requirements.

Infrastructure and certifications

When the platform is deployed in the cloud, it is hosted by Clouding.io, a cloud infrastructure provider with a data centre in Barcelona (Spain).

If the hospital deploys the platform on its own premises, its own infrastructure, security policy and certifications apply.

For your security assessment

If your IT team needs to complete a security questionnaire or review the architecture before contracting, we work through it with them, under a confidentiality agreement where needed.

Integration

Integration with the ERP, purchasing and clinical systems is designed with each hospital's IT team, through agreed interfaces, so that information flows without double entry.

Regulatory traceability

The product master and identification at reception and at the point of use support recording the UDI required by Regulation (EU) 2017/745 (MDR) and linking each device to the procedure and the patient. Each hospital remains responsible for its regulatory obligations; the platform supports how they are met in daily work.

Outside the European Union

For organisations outside the EU, the data processing agreement, the hosting location and the identification technology (for example the RFID frequency band) are adapted to the law of each country.

Responsible disclosure

If you believe you have found a security vulnerability in this website or in our platform, please write to info@synexiahealthcare.com with "Security" in the subject, a description and the steps to reproduce it. Please do not access or modify data that is not yours, and give us reasonable time to fix the issue before making it public. We will acknowledge your report and keep you informed. The contact details are also published in the standard file /.well-known/security.txt.

This website

This website only uses technical cookies and records enquiries in our customer management system with the safeguards described in the privacy policy.

Let's transform healthcare operations.