This document explains, without jargon, how we protect your patients' data. Support+ was designed from the start for Belgian practices, with their regulatory constraints in mind.
When AI comes up in a practice, the first question is the right one: "What about my patient data?" Here is the full answer.
| Data or action | Does Support+ touch it | Why |
|---|---|---|
| Patient name and emailTo answer their request | Yes | Only to handle the incoming request |
| General reason for contactExample: "appointment request" | Yes | To route it to the right person |
| Electronic medical recordHealthOne, CareConnect, etc. | No | No access, no connection |
| Diagnoses and prescriptions | No | Never processed, never stored |
| National register number | No | Not collected, not accessible |
| eHealth platform, BCSS, RSW/RSB | No | No connection to the health networks |
| Biometric or genetic data | No | Sensitive category, never processed |
As a practice, you are the "controller". Data IC is your "processor", acting within the framework you define.
You decide why and how your patients' data is used. You stay in control.
We do only what you ask, within the framework you define. Formalised in a DPA signed before any rollout.
Data processed only to deliver the requested service (Art. 6.1.b). No commercial purpose, no resale, no profiling.
We collect only what is needed: name, email, general reason, availability. Nothing more.
Automatic deletion after 12 months for records, 30 days for technical logs.
HTTPS/TLS 1.2+ encryption in transit, two-factor authentication, access logging.
You are alerted within 24 hours, and have 72 hours to notify the APD/GBA as the law requires. The APD/GBA, the Belgian Data Protection Authority, is the Belgian regulator responsible for enforcing the GDPR.
A Data Processing Agreement (Art. 28) is signed before anything is configured. It is your legal protection.
Many AI tools host their data in the United States, which is a real compliance problem for a practice. Our infrastructure stays in Europe.
Storage of administrative request records. Host certified SOC 2 Type II and ISO 27001, GDPR DPA signed.
Processing and routing of requests. Self-hosted under Data IC's exclusive control, no data held by a third party.
Understanding and classification of messages. Provider under a GDPR-equivalent DPA, data not used for training.
The AI Act classifies AI systems into four levels. The higher the risk, the stricter the obligations.
Mass surveillance, behavioural manipulation, social scoring.
Medical decisions, recruitment, credit. Mandatory certification and audits.
Systems that interact with people. Obligation to state that it is an AI.
Support+ sits hereBack-office tools with no interaction with a person.
Support+ talks with your patients to receive and route their requests. That is what places it in limited risk: the only strong obligation is transparency, and we already apply it.
It defines what Data IC can and cannot do with your practice's data. Nothing is configured before signature.
The data stays in Europe. Your front desk keeps the hand on every decision, with real-time visibility on the dashboard.
Returned in CSV or Excel format on request, then fully deleted within 30 days with a certificate.
The questions group practices ask us before signing. Grouped in four parts: compliance, security, rollout, day-to-day operation.
A free 30-minute video call. Together we check that Support+ matches your reality, regulatory as well as operational.
Book the call30 MIN · VIDEO · FREE · NO COMMITMENT