Security & compliance
Security and confidentiality are at the heart of WAICAH. We process healthcare data. We understand the responsibility that comes with it. We comply with the regulations, and we demonstrate that compliance.
Our commitments
Five simple commitments. Fully verifiable.
Hosting in France
Yes.
All your data is hosted exclusively in France by Skyloud, a certified HDS v2.0 hosting provider.
No audio storage
No.
Audio recordings are never stored. Only the structured medical report generated and validated by the physician is retained.
No AI training using your data
Never.
Neither your data nor your patients’ data are ever used to train our artificial intelligence models.
No data sales or sharing
Never.
Your data is never sold, shared, licensed, or transferred to any commercial, advertising, pharmaceutical, or third-party organization.
You remain the owner
Always.
Upon request, we provide a complete export of your data and permanently delete it from our systems.
Regulatory Framework
Built for French healthcare.
The platform has been designed so that physicians retain complete control over every medical report before it is integrated into the patient record.
GDPR Compliance
WAICAH complies with the General Data Protection Regulation (GDPR) and follows CNIL recommendations regarding healthcare data processing. All processing activities are documented within our GDPR processing register.
HDS v2.0 Certification
Healthcare data hosting is entrusted to Skyloud, a hosting provider certified under HDS v2.0. HDS v2.0 is the new French healthcare hosting framework effective since May 16, 2026, introducing strengthened requirements for the protection of healthcare data.
ISO 27001
To be displayed if applicable through Skyloud certification.
French Public Health Code
WAICAH respects medical confidentiality as defined under Article L.1110-4 of the French Public Health Code.
Where and how
Hosted in France. Encrypted. Audited.
All your data and your patients’ data are stored in France on HDS v2.0 certified servers. Data is encrypted both at rest and in transit. Access is restricted, logged, and regularly audited.
Physician
WAICAH
(French HDS v2.0 Certified Infrastructure)
Patient Medical Record
Padlock icons displayed on each connection to symbolize encryption.
Ownership & portability
You own it. you control it.
-
No AI RetrainingYour medical reports and your patients' information are NEVER used to train our artificial intelligence.
-
Data Portability
At any time, you may request a complete export of your data in a standard format such as JSON or CSV. Within 30 days of your request, we permanently delete all your data from our systems.
-
Personal Audit Trail
You may audit access to your data directly through your WAICAH interface. Every login, every modification, and every access event is logged and traceable.
Our data protection officer
An independent external DPO.
In accordance with GDPR requirements for healthcare data processing, WAICAH has appointed an independent external Data Protection Officer (DPO): Lexagone. Lexagone is a French data protection and compliance firm specialized in healthcare data governance. They continuously monitor our compliance framework, audit our practices, and serve as the primary point of contact for all data protection matters.
Security FAQ
Where is my patients' data stored?
All data is encrypted and hosted on HDS v2.0 certified infrastructure located in France.
What protections exist against cyberattacks?
Several layers of protection are implemented:
- Encryption at rest and in transit
- Strong physician authentication
- Access logging
- Regular penetration testing performed by independent third parties
- Business continuity and disaster recovery plans
Are audio recordings stored?
No.
- Audio is processed in real time to generate the medical report and is then deleted.
- Only the structured report validated by the physician is retained.
Is my data sold or shared with third parties?
Never.
Neither your data nor your patients’ data are sold, shared, or transferred to commercial, advertising, pharmaceutical, or third-party organizations.
Is my data used to train your AI?
No.
- Our models are trained using public and anonymized datasets.
- Your data never contributes to model training.
Who can access my patients' data?
- Only you and the healthcare professionals to whom you explicitly grant access.
- Our technical team cannot access the content of your medical reports.
Must I inform my patient that I use an AI-powered listening tool?
Yes.
- For transparency and GDPR compliance, a simple verbal consent should be obtained at the beginning of the consultation.
- WAICAH does not store audio recordings.
- Only the structured medical report is generated.
What happens to my data if I leave WAICAH?
You remain the owner.
Upon request, we provide a complete export of your data and permanently delete it from our systems within 30 days, in accordance with GDPR requirements.
How can I exercise my GDPR rights?
- You may exercise your rights of access, correction, objection, deletion, and portability at any time by contacting our Data Protection Officer.
- Response time: within 30 days maximum.
- DPO email address to be confirmed with Marc.
What happens in the event of a data breach?
- WAICAH follows a documented incident response procedure.
- We notify the CNIL and affected individuals within 72 hours, in accordance with Article 33 of the GDPR.
- Our incident response plan is reviewed annually.

