Previza Previza
Data Security

How Previza protects patient data

Previza processes sensitive medical information. This page walks through, step by step, what happens to a patient's data — from consent all the way to deletion.

1. Consent

The patient explicitly confirms, at the start of the conversation, that they agree to their answers being used to generate the summary.

2. Encryption

Data is encrypted to the AES standard, both in transit — between the patient's device and Previza's infrastructure — and at rest.

3. EU-based processing

Structuring the answers into the summary happens entirely on infrastructure hosted within the European Union.

4. Limited access

The summary is visible only to the doctor or clinic authorized for that specific appointment.

GDPR

GDPR compliance, explained step by step

The General Data Protection Regulation (GDPR) sets strict rules for collecting and processing medical data. Previza is built to meet these requirements at every step of the process.

Explicit consent

The patient must actively confirm, at the start of the conversation, that they agree to their data being processed. Without this confirmation, the conversation does not continue.

Limited processing purpose

The data collected is used exclusively to generate the patient history summary — never for other purposes such as marketing, research, or resale.

Access limited exclusively to the clinic

The generated summary goes directly to the clinic. Previza retains no access to its content after delivery, which removes the need for a separate deletion request to Previza.

Zero-retention policy

Data is never stored on Previza's servers. The summary is delivered to the clinic, and Previza retains no access to it after delivery — it is not stored, not shared, and not used to train AI models.

What Previza Doesn't Store

The explicit limits of our data processing

No storage on Previza's servers

The retention policy is zero: data is not stored on Previza's servers once the summary has been generated and delivered to the clinic.

No sharing and no AI model training

The summary is received exclusively by the clinic. Previza does not share data with third parties and does not use it to train AI models.

No automated clinical decisions

Previza structures the information the patient provides. It does not make diagnoses or clinical decisions on the doctor's behalf.

Security Questions

Details on data protection

Where is patient data hosted?

On infrastructure hosted entirely within the European Union, in line with GDPR requirements for medical data.

Who has access to the generated summary? +
Is the data encrypted? +
How long does Previza keep a patient's data? +
Does Previza use patient data to train AI models? +
Can a patient withdraw their consent? +
Is Previza externally audited for security? +

More questions about security?

The Previza team can provide additional compliance documentation on request, for clinics and clinic networks.