Support+ Medical · Compliance
FR·NL·EN30-min meeting
← Back to Support+ Medical

GDPR and EU AI Act compliant. Here is how, in plain language.

This document explains, without jargon, how we protect your patients' data. Support+ was designed from the start for Belgian practices, with their regulatory constraints in mind.

GDPR (EU) 2016/679
Compliant, Art. 28 processor
EU AI Act 2024/1689
Limited risk, Art. 50 transparency
Hosting
European infrastructure
Belgian law of 30/07/2018
Compliant
01The most important boundary

What Support+ processes, and what it never touches.

When AI comes up in a practice, the first question is the right one: "What about my patient data?" Here is the full answer.

Data or actionDoes Support+ touch itWhy
Patient name and emailTo answer their requestYesOnly to handle the incoming request
General reason for contactExample: "appointment request"YesTo route it to the right person
Electronic medical recordHealthOne, CareConnect, etc.NoNo access, no connection
Diagnoses and prescriptionsNoNever processed, never stored
National register numberNoNot collected, not accessible
eHealth platform, BCSS, RSW/RSBNoNo connection to the health networks
Biometric or genetic dataNoSensitive category, never processed
In short. Support+ works in support of your front desk. It receives and sorts incoming requests without accessing the medical record. Your secretary stays in control and steps in on anything that needs a human eye.
02What this changes in practice

GDPR: the six obligations, and how we meet them.

As a practice, you are the "controller". Data IC is your "processor", acting within the framework you define.

Your role
Controller

You decide why and how your patients' data is used. You stay in control.

Our role
Processor · Data IC

We do only what you ask, within the framework you define. Formalised in a DPA signed before any rollout.

Legal basis

Data processed only to deliver the requested service (Art. 6.1.b). No commercial purpose, no resale, no profiling.

Minimisation

We collect only what is needed: name, email, general reason, availability. Nothing more.

Limited retention

Automatic deletion after 12 months for records, 30 days for technical logs.

Technical security

HTTPS/TLS 1.2+ encryption in transit, two-factor authentication, access logging.

Breach notification

You are alerted within 24 hours, and have 72 hours to notify the APD/GBA as the law requires. The APD/GBA, the Belgian Data Protection Authority, is the Belgian regulator responsible for enforcing the GDPR.

DPA signed first

A Data Processing Agreement (Art. 28) is signed before anything is configured. It is your legal protection.

What about your patients' rights? They are your responsibility, as the controller. If a patient contacts us to exercise them, we forward the request to you within 72 hours.
Access
Know which data is processed
Rectification
Correct inaccurate data
Erasure
Right to be forgotten on request
Portability
Export in a standard format
Objection
Refuse certain processing
Restriction
Temporarily freeze processing
03Your data stays in Europe

A European infrastructure.

Many AI tools host their data in the United States, which is a real compliance problem for a practice. Our infrastructure stays in Europe.

Database
Dublin, Ireland (EU)

Storage of administrative request records. Host certified SOC 2 Type II and ISO 27001, GDPR DPA signed.

Orchestration
Dedicated EU server

Processing and routing of requests. Self-hosted under Data IC's exclusive control, no data held by a third party.

Language model
Processing governed by contract (DPA)

Understanding and classification of messages. Provider under a GDPR-equivalent DPA, data not used for training.

Contractual guarantee. The data remains governed by a data processing agreement (DPA). Any transfer outside the European Union is covered by the European Commission's standard contractual clauses, and your data is never used to train AI models. If the infrastructure changes, you are informed 30 days in advance, with the option to terminate without penalty.
04Phased application until 2027

EU AI Act: Support+ falls under limited risk.

The AI Act classifies AI systems into four levels. The higher the risk, the stricter the obligations.

Unacceptable
Prohibited

Mass surveillance, behavioural manipulation, social scoring.

High
Heavy obligations

Medical decisions, recruitment, credit. Mandatory certification and audits.

Limited
Transparency required

Systems that interact with people. Obligation to state that it is an AI.

Support+ sits here
Minimal
No obligations

Back-office tools with no interaction with a person.

Support+ talks with your patients to receive and route their requests. That is what places it in limited risk: the only strong obligation is transparency, and we already apply it.

The patient knows they are talking to an AIThe agent states it at the start of every exchange (Art. 50), ahead of the August 2026 deadline.
No medical decisionsSupport+ sorts administrative requests, never symptoms or diagnoses.
Systematic human supervisionAny ambiguous or out-of-scope message is passed to the front desk before action.
No health profilingContact reasons stay generic, with no link to a state of health.
No connection to medical toolsNo EMR, no eHealth, no BCSS.
Traceability and monitoringLogs kept for 30 days, and active regulatory monitoring with notice within 30 days if a new obligation arises.
05Concrete, not theoretical

What this means for your practice.

Before we start

A DPA is signed

It defines what Data IC can and cannot do with your practice's data. Nothing is configured before signature.

During operation

You keep control

The data stays in Europe. Your front desk keeps the hand on every decision, with real-time visibility on the dashboard.

If you stop

Data returned

Returned in CSV or Excel format on request, then fully deleted within 30 days with a certificate.

06The questions we get asked

Frequently asked questions.

The questions group practices ask us before signing. Grouped in four parts: compliance, security, rollout, day-to-day operation.

Compliance, GDPR & AI Act

Will the agent answer my patients in my place?
No. Support+ spares your front desk from handling the same repetitive requests fifty times a day (acknowledgements, opening hours, call-back requests). Any complex, sensitive or ambiguous message is passed to your team. Your front desk keeps the last word.
Will my data be used to train the AI model?
No. The data processed by Support+ is not used to improve the AI model we rely on. This is contractually guaranteed in the DPA signed with our provider. Your data does not leave your perimeter.
If the Belgian Data Protection Authority (APD/GBA) audits me, am I covered?
You hold a signed DPA (Art. 28), clear processing documentation, verifiable European hosting and a documented AI Act classification. That is what the APD/GBA asks for during an audit.
What if the regulations change?
The AI Act applies in stages until 2027. Data IC monitors the texts and informs you quickly of any new obligation that concerns you. If a change affects the service, you can terminate without penalty.
What is Data IC's contractual liability?
We are liable for what depends on us: a bug, a routing error, a system malfunction. Liability is capped at 12 months of subscription, adjustable at signature according to the stakes you identify. What is not ours: the medical decision, the content of the consultation, the patient record. Those remain the responsibility of the practitioner and of your EMR.

Security & operational continuity

What happens in case of an outage?
Our monitoring detects incidents within minutes and alerts us by SMS. If the service is affected, the secretary immediately receives an SMS with the fallback instructions. Every building block has a built-in plan B: calls forwarded to a backup number, calendar available in read-only mode, requests queued until everything is back. As for availability, the patient-facing service runs 24/7: that is precisely the promise of Support+. Our team acts without delay on critical incidents, and picks up adjustments during business hours. During the first month, a weekly check-in with your secretary fine-tunes the system to your real flow.
What happens if you stop the service?
30 days' notice after the minimum term. Your data belongs to you and remains retrievable at any time. Our workflows and technical configurations remain our intellectual property (that is our know-how). On written request, you get your data back within 7 working days (CSV or Excel for the records, standard calendar format for the schedules). Permanent deletion from our systems within 30 days after confirmation that the exports have safely reached you, with a signed attestation. No deliberate lock-in.

Rollout in the practice

Who creates the email addresses the agent will use?
Not us. A practitioner's mailbox can contain patient data: it is better that the practice keeps ownership of it. Two possible options: a professional domain (for example secretariat@yourpractice.be) with a professional suite such as Google Workspace or Microsoft 365, or each practitioner's existing emails. We then configure the dedicated mailbox the agent reads and handles.
What training is planned for our team?
The rollout includes a 2-hour dashboard workshop for the secretary (video call or on site) and a 1-hour workshop for 3 to 5 pilot practitioners. Then three months of support: a 30-minute weekly check-in with the secretary for the first four weeks, fortnightly afterwards, and a priority direct email line. For solo or paramedical practices, the format is lighter: a remote briefing, then 30 minutes of hands-on onboarding.
How does a POC (proof of concept) work?
Each POC is scoped case by case, with you, at the first meeting: perimeter, success indicators, conditions and timing depend on the size of the practice, its organisation and its busiest slots. We then deploy on a reduced perimeter in real conditions, with volunteer pilot practitioners. If it does not go further, you return to your previous tool overnight, with no strings attached.
How do you handle multi-site practices?
At the start, we spend 1 hour together mapping your organisation: practitioners × specialities × sites, coordination rules, reasons to exclude from automatic booking, reserved time blocks. You leave with a shared routing reference document (viewable and editable at your own pace). Each practitioner can have several sites, with their own hours and procedure durations. If a practitioner has to cancel at the last minute, all of the day's patients are notified automatically and invited to rebook. Certain sensitive reasons (first consultation, infiltration, examinations) can systematically go through your front desk before confirmation.

Day-to-day operation

What real autonomy rate for the agent?
No fixed figure promised in advance: it depends on the complexity of the requests specific to the practice and on the maturity of the rollout. What is contractually guaranteed: when the agent does not understand a request, it rephrases its question, otherwise it transfers the request to your secretary with a summary of what it understood, and a ticket appears on the dashboard with a "call back" status. No call is lost in silence.
How do appointment reminders work?
An automatic reminder is sent before each appointment. If someone cancels, the slot is immediately released and offered to the waiting list. The list works by SMS: the first patient to confirm takes the slot. Three logics to choose from: round robin, seniority, or a priority set by the practice.
How are appointments distributed between practitioners?
If the patient asks for a specific practitioner, they get that practitioner's slots. If they ask for a speciality, the agent distributes according to the mode you have chosen: fairness (by default, calendars filled evenly), priority to a designated practitioner, or first available slot. Each practitioner can have their own rules: cap on new patients per week, excluded reasons, reserved time blocks (example: Wednesday morning = emergencies and post-operative follow-ups only), procedure duration per reason. In a multi-site setup, the agent can offer another site if the wait at the first one becomes too long.
What do you do about no-shows (patients absent without notice)?
The automatic reminder before the appointment already mechanically reduces the no-show rate. We do not force confirmation: if the patient does not reply, their slot stays reserved. No-show billing, for its part, stays in your usual tool. Technically, we can trigger a follow-up email with a payment link, but always with practitioner approval, never blindly automatic.
First step, no commitment

A question about compliance?
We answer in plain language.

A free 30-minute video call. Together we check that Support+ matches your reality, regulatory as well as operational.

Book the call

30 MIN · VIDEO · FREE · NO COMMITMENT

Book a free call →