GDPR
Neogenic is built for the EU General Data Protection Regulation. We store your clinic's data in the EU, act only on your instructions, and give you the tools to respect your clients' rights.
How Neogenic meets GDPR
Clear roles
Your clinic decides how the contacts, leads and records it keeps in Neogenic are used: you are the controller. Scality Ltd, which provides Neogenic, processes that data only to deliver the service to you, under our standard Data Processing Agreement. Your clinic accepts it during onboarding.
Lawful and transparent
We use your clinic's data only to provide Neogenic. We never sell it, use it for our own marketing, or use it to train AI models. Our privacy notice explains what we process about the people who use Neogenic.
Data minimisation
Neogenic collects what the features you use need. Our assistant Neo only sees the records the signed-in staff member is allowed to see, for the request they make. The current version of Neogenic does not accept health or patient information.
Data stored in the EU
Your clinic's primary data is stored in the European Union (Stockholm, Sweden), and our application servers run in the EU (Amsterdam, Netherlands). A few services we use, such as email delivery and the AI model provider, may process data outside the EEA. Every such transfer is covered by the EU Standard Contractual Clauses or the EU–US Data Privacy Framework. See the full subprocessor list.
Rights of your clients
Neogenic helps your clinic respond to access, correction, deletion and objection requests. Every marketing email carries an unsubscribe link, and opt-outs apply across your whole clinic. Staff can record an objection received by phone or email on the contact's page.
Security by design
- Encryption in transit and at rest.
- Role-based permissions, and clinics separated in the database.
- Two-factor authentication for our administrators.
- Daily backups.
- An audit trail for administrative access.
- No Neogenic employee reads your clinic's data without your request or a security reason, and every such access is recorded.
Retention and deletion
We keep data only as long as needed. When a clinic leaves, it chooses return or deletion: we provide an export on request within 30 days, then delete the live copies. Our privacy notice says how long we keep account information.
Breach notification
We have a documented incident procedure. If a personal-data breach affects your clinic's data, we notify your incident contact without undue delay and within 48 hours.
Privacy contact
We have assessed that we are not required to appoint a Data Protection Officer. Questions go to our privacy contact: privacy@neogenic.ai.
Frequently asked questions
Is Neogenic GDPR compliant?
Yes, for the current Neogenic service. It meets GDPR through the measures on this page, our Data Processing Agreement and our internal records. Neogenic is not "GDPR certified": no general GDPR certificate exists, and we don't claim one.
Can we store patient health information in Neogenic?
Not yet. The current version is for operations and marketing without health data. Support for patient records will come in a later version, with its own agreement.
Where can I see who processes our data?
On our subprocessor list. We notify your privacy contact at least 14 days before adding or replacing a subprocessor.
Can you help with our DPIA?
Yes. Email privacy@neogenic.ai and we'll share what you need about how Neogenic processes data.