Compliance

Built for GDPR and the EU AI Act — from the first call.

Not bolted on. A readiness checklist per store, the documents generated for you, and the technical controls underneath — encryption, per-store isolation, and a full audit trail.

Compliance & Readiness12 of 15 required done
Data Processing Agreement signedDone
Record of Processing (ROPA) on fileDone
DPIA completedDone
GDPR + AI staff briefing (AI Act Art 4)In progress
AI self-disclosure live (AI Act Art 50)Done
Counter privacy notice displayedOutstanding
The technical guarantees

The controls, not just the claims.

The protections that sit under every call and message — the same ones the product runs on today.

Field-level encryptionPII encrypted at rest.
Per-store isolation (RLS)Row-level security, enforced.
Full audit trailEvery action attributable.
DSAR & retentionAutomated handling.
Signed webhooksVerified server-to-server.
DPA / DPIA / ROPAGenerated in-app.
Readiness, tracked

Go-live is a checklist, not a promise.

A per-store readiness list covering data protection, AI & staff training and incident handling — with the DPA, DPIA and ROPA generated in-app, and staff acknowledgements recorded.

The AI self-disclosure (EU AI Act Art 50) is a tracked, live item.

Incidents are logged and tracked to GDPR Articles 33 / 34.

Compliance & Readiness12 of 15 required done
Data Processing Agreement signedDone
Record of Processing (ROPA) on fileDone
DPIA completedDone
GDPR + AI staff briefing (AI Act Art 4)In progress
AI self-disclosure live (AI Act Art 50)Done
Counter privacy notice displayedOutstanding

The AI never dispenses. Your pharmacist always decides.

Every automatic action stays reviewable, and a person makes every clinical call.

See the compliance pack.

We’ll walk your DPO through the checklist, the generated documents and the controls — before a single call goes live.